312-50V13 · Question #18
When analyzing the IDS logs, the system administrator noticed an alert was logged when the external router was accessed from the administrator's Computer to update the router configuration. What…
The correct answer is D. False positive. Explanation Option D (False Positive) is correct because the IDS flagged a legitimate administrative activity - an authorized administrator updating the router configuration - as a potential threat. Since the activity was benign and authorized, the alert was triggered in error…
Question
Options
- AFalse negative
- BTrue negative
- CTrue positive
- DFalse positive
How the community answered
(27 responses)- B4% (1)
- C4% (1)
- D93% (25)
Explanation
Explanation
Option D (False Positive) is correct because the IDS flagged a legitimate administrative activity - an authorized administrator updating the router configuration - as a potential threat. Since the activity was benign and authorized, the alert was triggered in error, which is the definition of a false positive (an alarm raised for something that is not actually an attack).
Why the distractors are wrong:
- A (False Negative): This would mean a real attack occurred but the IDS failed to detect it - the opposite scenario.
- B (True Negative): This means no attack occurred and no alert was triggered - but here, an alert was triggered.
- C (True Positive): This would mean a real attack occurred and the IDS correctly detected it - but the admin's action was legitimate, not malicious.
Memory Tip
Think of it like a car alarm going off when the owner unlocks their own car - the alarm fired (positive), but there was no real threat (false). Whenever a legitimate action triggers an IDS alert, it's a False Positive. Use the phrase: "False Positive = Crying Wolf."
Topics
Community Discussion
No community discussion yet for this question.