ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 71 - ECSS discussion

Report
Export

Jay, a network administrator, was monitoring traffic flowing through an IDS. Unexpectedly, he received an event triggered as an alarm, although there is no active attack in progress.

Identify the type of IDS alert Jay has received in the above scenario.

A.

True negative alert

Answers
A.

True negative alert

B.

False negative alert

Answers
B.

False negative alert

C.

True positive alert

Answers
C.

True positive alert

D.

False positive alert

Answers
D.

False positive alert

Suggested answer: D

Explanation:

In the given scenario, Jay received an alarm from the IDS even though there was no active attack. This situation corresponds to afalse positive alert. A false positive occurs when the IDS incorrectly identifies benign or legitimate traffic as malicious or suspicious. It can lead to unnecessary alerts and additional workload for network administrators.

asked 24/10/2024
Chan Man Wong
43 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first