nerdexam
CompTIA

CAS-002 · Question #125

An intrusion detection system logged an attack attempt from a remote IP address. One week later, the attacker successfully compromised the network. Which of the following MOST likely occurred?

The correct answer is D. No one was reviewing the IDS event logs. The IDS correctly detected and logged the attack attempt, but no one reviewed or acted on the alert, which allowed the attacker to return a week later and successfully compromise the network.

Enterprise Security

Question

An intrusion detection system logged an attack attempt from a remote IP address. One week later, the attacker successfully compromised the network. Which of the following MOST likely occurred?

Options

  • AThe IDS generated too many false negatives.
  • BThe attack occurred after hours.
  • CThe IDS generated too many false positives.
  • DNo one was reviewing the IDS event logs.

How the community answered

(30 responses)
  • A
    3% (1)
  • B
    17% (5)
  • C
    10% (3)
  • D
    70% (21)

Why each option

The IDS correctly detected and logged the attack attempt, but no one reviewed or acted on the alert, which allowed the attacker to return a week later and successfully compromise the network.

AThe IDS generated too many false negatives.

False negatives occur when an IDS fails to detect a real attack; this scenario explicitly states the IDS did log the attack attempt, which means false negatives were not the cause of the eventual compromise.

BThe attack occurred after hours.

The time of the attack is irrelevant if logs are reviewed regularly - there is no indication in the scenario that after-hours monitoring gaps existed or contributed to the outcome.

CThe IDS generated too many false positives.

False positives are benign events incorrectly flagged as malicious; the IDS accurately identified a real attack attempt, so alert fatigue from false positives is not supported by the scenario.

DNo one was reviewing the IDS event logs.Correct

An IDS is only effective if its alerts are actively monitored and investigated - the attack attempt was logged, confirming detection worked correctly, but the absence of any response indicates that no one reviewed the event logs, leaving the vulnerability unaddressed and giving the attacker time to plan and execute a successful follow-up intrusion.

Concept tested: IDS alert monitoring and security event response process

Source: https://csrc.nist.gov/publications/detail/sp/800-94/final

Topics

#IDS#log monitoring#false positives#incident response

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice