200-201 · Question #507
An analyst see that this security alert "Default-Botnet-Communication-Detection-By-Endpoint" has been raised from the IPS. The analyst checks and finds that an endpoint communicates to the C&C. How…
The correct answer is A. true positive. A true positive occurs when a security system correctly detects a real threat. In this case, the "Default-Botnet-Communication-Detection-By-Endpoint" alert was triggered by the Intrusion Prevention System (IPS), and further investigation confirmed that an endpoint is indeed…
Question
An analyst see that this security alert "Default-Botnet-Communication-Detection-By-Endpoint" has been raised from the IPS. The analyst checks and finds that an endpoint communicates to the C&C. How must an impact from this event be categorized?
Options
- Atrue positive
- Btrue negative
- Cfalse positive
- Dfalse negative
How the community answered
(42 responses)- A90% (38)
- B2% (1)
- C2% (1)
- D5% (2)
Explanation
A true positive occurs when a security system correctly detects a real threat. In this case, the "Default-Botnet-Communication-Detection-By-Endpoint" alert was triggered by the Intrusion Prevention System (IPS), and further investigation confirmed that an endpoint is indeed communicating with a Command and Control (C&C) server. Since the detection accurately identified malicious activity, it is classified as a true positive.
Topics
Community Discussion
No community discussion yet for this question.