nerdexam
Cisco

200-201 · Question #507

An analyst see that this security alert "Default-Botnet-Communication-Detection-By-Endpoint" has been raised from the IPS. The analyst checks and finds that an endpoint communicates to the C&C. How…

The correct answer is A. true positive. A true positive occurs when a security system correctly detects a real threat. In this case, the "Default-Botnet-Communication-Detection-By-Endpoint" alert was triggered by the Intrusion Prevention System (IPS), and further investigation confirmed that an endpoint is indeed…

Submitted by tarun92· Mar 6, 2026Security Monitoring

Question

An analyst see that this security alert "Default-Botnet-Communication-Detection-By-Endpoint" has been raised from the IPS. The analyst checks and finds that an endpoint communicates to the C&C. How must an impact from this event be categorized?

Options

  • Atrue positive
  • Btrue negative
  • Cfalse positive
  • Dfalse negative

How the community answered

(42 responses)
  • A
    90% (38)
  • B
    2% (1)
  • C
    2% (1)
  • D
    5% (2)

Explanation

A true positive occurs when a security system correctly detects a real threat. In this case, the "Default-Botnet-Communication-Detection-By-Endpoint" alert was triggered by the Intrusion Prevention System (IPS), and further investigation confirmed that an endpoint is indeed communicating with a Command and Control (C&C) server. Since the detection accurately identified malicious activity, it is classified as a true positive.

Topics

#true positive#false positive#security alerts#incident validation

Community Discussion

No community discussion yet for this question.

Full 200-201 Practice