ExamGecko
Question list
Search
Search

Question 563 - CISM discussion

Report
Export

Which of the following trends would be of GREATEST concern when reviewing the performance of an organization's intrusion detection systems (IDSs)?

A.
Decrease in false positives
Answers
A.
Decrease in false positives
B.
Increase in false positives
Answers
B.
Increase in false positives
C.
Increase in false negatives
Answers
C.
Increase in false negatives
D.
Decrease in false negatives
Answers
D.
Decrease in false negatives
Suggested answer: C

Explanation:

An increase in false negatives would be of greatest concern when reviewing the performance of an organization's IDSs, because it means that the IDSs are failing to detect and alert on actual attacks that are occurring on the network. False negatives can lead to serious security breaches, data loss, reputational damage, and legal liabilities for the organization. False positives, on the other hand, are alerts that are triggered by benign or normal activities that are mistaken for attacks. False positives can cause annoyance, inefficiency, and desensitization, but they do not pose a direct threat to the security of the network. Therefore, a decrease in false positives would be desirable, and an increase in false positives would be less concerning than an increase in false negatives.

Reference= CISM Review Manual, 16th Edition, page 2231; Intrusion Detection Systems | NIST

asked 01/10/2024
Zulkarnain Hashim
39 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first