ExamGecko
Question list
Search
Search

Related questions











Question 131 - 200-201 discussion

Report
Export

Which action should be taken if the system is overwhelmed with alerts when false positives and false negatives are compared?

A.

Modify the settings of the intrusion detection system.

Answers
A.

Modify the settings of the intrusion detection system.

B.

Design criteria for reviewing alerts.

Answers
B.

Design criteria for reviewing alerts.

C.

Redefine signature rules.

Answers
C.

Redefine signature rules.

D.

Adjust the alerts schedule.

Answers
D.

Adjust the alerts schedule.

Suggested answer: B

Explanation:

When a system is overwhelmed with alerts, designing criteria for reviewing alerts can help prioritize and manage them more effectively.This approach allows for a structured review process that can distinguish between false positives, false negatives, and legitimate alerts, reducing the overall number of alerts that require attention3.

asked 07/10/2024
Roberto Pili
29 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first