nerdexam
EC-Council

312-39 · Question #195

312-39 Question #195: Real Exam Question with Answer & Explanation

The correct answer is D. False Negative Incidents. A false negative incident in the context of a Security Operations Center (SOC) is when an actual attack or intrusion occurs, but the SOC analyst fails to detect any suspicious events or indicators of compromise. This means that the security measures in place did not work as inten

Question

David is a SOC analyst in Karen Tech. One day an attack is initiated by the intruders but David was not able to find any suspicious events. This type of incident is categorized into ?

Exhibit

312-39 question #195 exhibit

Options

  • ATrue Positive Incidents
  • BFalse positive Incidents
  • CTrue Negative Incidents
  • DFalse Negative Incidents

Explanation

A false negative incident in the context of a Security Operations Center (SOC) is when an actual attack or intrusion occurs, but the SOC analyst fails to detect any suspicious events or indicators of compromise. This means that the security measures in place did not work as intended, and the attack went unnoticed. In David’s case, since an attack was initiated and he was not able to find any suspicious events, it is categorized as a false negative incident. This is a critical type of incident because it indicates a failure in the detection capabilities of the SOC, potentially allowing the intruder to cause harm without outlined in the EC-Council’s Certified SOC Analyst (CSA) training and certification program. The program covers the different types of incidents that can be encountered in a SOC, including true positives, false positives, true negatives, and false negatives, and how to identify and respond to

Community Discussion

No community discussion yet for this question.

Full 312-39 Practice