nerdexam
Cisco

200-201 · Question #181

What is the impact of false positive alerts on business compared to true positive?

The correct answer is C. False-positive alerts are detected by confusion as potential attacks, while true positives are attack. False-positive alerts incorrectly flag legitimate activity as a potential attack, leading to wasted resources, while true-positive alerts correctly identify actual attacks, prompting necessary responses.

Submitted by neha2k· Mar 6, 2026Security Monitoring

Question

What is the impact of false positive alerts on business compared to true positive?

Options

  • ATrue positives affect security as no alarm is raised when an attack has taken place, while false
  • BTrue-positive alerts are blocked by mistake as potential attacks, while False-positives are actual
  • CFalse-positive alerts are detected by confusion as potential attacks, while true positives are attack
  • DFalse positives alerts are manually ignored signatures to avoid warnings that are already

How the community answered

(53 responses)
  • A
    4% (2)
  • B
    2% (1)
  • C
    92% (49)
  • D
    2% (1)

Why each option

False-positive alerts incorrectly flag legitimate activity as a potential attack, leading to wasted resources, while true-positive alerts correctly identify actual attacks, prompting necessary responses.

ATrue positives affect security as no alarm is raised when an attack has taken place, while false

True positives are alarms raised when an attack has occurred, not when no alarm is raised. False positives do not represent a lack of alarm during an attack.

BTrue-positive alerts are blocked by mistake as potential attacks, while False-positives are actual

True-positive alerts correctly identify actual attacks; they are not blocked by mistake. False-positives are misidentified benign events, not actual attacks.

CFalse-positive alerts are detected by confusion as potential attacks, while true positives are attackCorrect

False-positive alerts are instances where a security system mistakenly identifies benign activity as malicious, causing confusion and unnecessary investigation. True-positive alerts, conversely, accurately detect actual security incidents or attacks, allowing for appropriate action.

DFalse positives alerts are manually ignored signatures to avoid warnings that are already

False-positive alerts are typically investigated and then ignored if deemed harmless, not manually ignored signatures to avoid warnings.

Concept tested: Security alert types (False Positive vs True Positive)

Source: https://learn.microsoft.com/en-us/security/benchmark/azure/baselines/security-center-security-recommendations

Topics

#false positive#true positive#alert analysis#security operations

Community Discussion

No community discussion yet for this question.

Full 200-201 Practice