nerdexam
EC-Council

312-50V10 · Question #277

A network administrator received an administrative alert at 3:00 a.m. from the intrusion detection system. The alert was generated because a large number of packets were coming into the network over p

The correct answer is D. False positives. When an IDS generates an alert but no actual attack has occurred, it is classified as a false positive - the system incorrectly flagged legitimate traffic as malicious.

Evading IDS, Firewalls, and Honeypots

Question

A network administrator received an administrative alert at 3:00 a.m. from the intrusion detection system. The alert was generated because a large number of packets were coming into the network over ports 20 and 21. During analysis, there were no signs of attack on the FTP servers. How should the administrator classify this situation?

Options

  • ATrue negatives
  • BFalse negatives
  • CTrue positives
  • DFalse positives

How the community answered

(18 responses)
  • A
    6% (1)
  • B
    6% (1)
  • D
    89% (16)

Why each option

When an IDS generates an alert but no actual attack has occurred, it is classified as a false positive - the system incorrectly flagged legitimate traffic as malicious.

ATrue negatives

A true negative means no alert was generated AND no attack occurred, which does not apply here because an alert was generated.

BFalse negatives

A false negative means an attack actually occurred but the IDS failed to generate an alert, which is the opposite of this situation.

CTrue positives

A true positive means an alert was generated AND a real attack was confirmed, but analysis revealed no actual attack in this scenario.

DFalse positivesCorrect

A false positive occurs when a security control raises an alarm for benign activity that was misidentified as an attack. In this scenario the IDS fired on high-volume FTP traffic (ports 20/21), but investigation confirmed no actual attack on the FTP servers, meaning the alert was incorrect. This is the definition of a false positive and represents a detection accuracy problem that can lead to alert fatigue.

Concept tested: IDS alert classification - false positive identification

Source: https://docs.cisco.com/en/us/solutions/enterprise/security/ids-ips-design-guide/12441-idsips-desguide-ch5.html

Topics

#IDS#false positive#intrusion detection#alert classification

Community Discussion

No community discussion yet for this question.

Full 312-50V10 Practice