ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 147 - CS0-003 discussion

Report
Export

An organization enabled a SIEM rule to send an alert to a security analyst distribution list when ten failed logins occur within one minute. However, the control was unable to detect an attack with nine failed logins. Which of the following best represents what occurred?

A.
False positive
Answers
A.
False positive
B.
True negative
Answers
B.
True negative
C.
False negative
Answers
C.
False negative
D.
True positive
Answers
D.
True positive
Suggested answer: C

Explanation:

The correct answer is C. False negative.

A false negative is a situation where an attack or a threat is not detected by a security control, even though it should have been. In this case, the SIEM rule was unable to detect an attack with nine failed logins, which is below the threshold of ten failed logins that triggers an alert. This means that the SIEM rule missed a potential attack and failed to alert the security analysts, resulting in a false negative.

A false positive is a situation where a benign or normal activity is detected as an attack or a threat by a security control, even though it is not. A true negative is a situation where a benign or normal activity is not detected as an attack or a threat by a security control, as expected. A true positive is a situation where an attack or a threat is detected by a security control, as expected. These are not the correct answers for this question.

asked 02/10/2024
Jaimie Lloyd
39 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first