ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 371 - CAS-004 discussion

Report
Export

A security engineer is working for a service provider and analyzing logs and reports from a new EDR solution, which is installed on a small group of workstations. Later that day, another security engineer receives an email from two developers reporting the software being used for development activities is now blocked. The developers have not made any changes to the software being used. Which of the following is the EDR reporting?

A.
True positive
Answers
A.
True positive
B.
False negative
Answers
B.
False negative
C.
False positive
Answers
C.
False positive
D.
True negative
Answers
D.
True negative
Suggested answer: C

Explanation:

When an EDR (Endpoint Detection and Response) system flags legitimate software as malicious, it is a false positive. This occurs when the EDR incorrectly identifies normal, non-malicious activity as a threat. The scenario described indicates that the development software was blocked even though there were no changes to the software, which suggests a false positive by the EDR system.

asked 02/10/2024
Daniel Vong
42 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first