ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 431 - SY0-601 discussion

Report
Export

A security analyst receives an alert from the company's S1EM that anomalous activity is coming from a local source IP address of 192 168 34.26 The Chief Information Security Officer asks the analyst to block the originating source Several days later another employee opens an internal ticket stating that vulnerability scans are no longer being performed property. The IP address the employee provides is 192 168.34 26. Which of the following describes this type of alert?

A.
True positive
Answers
A.
True positive
B.
True negative
Answers
B.
True negative
C.
False positive
Answers
C.
False positive
D.
False negative
Answers
D.
False negative
Suggested answer: C

Explanation:

A false positive is a type of alert that indicates a security incident when there is none. It can be caused by misconfigured or overly sensitive security tools or systems that generate false or irrelevant alerts. In this case, the alert from the company's SIEM that Mimikatz attempted to run on the remote systems was a false positive because it was triggered by a legitimate vulnerability scanning tool that uses Mimikatz as part of its functionality.

asked 02/10/2024
Luis Raul Juarez Cosio
38 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first