nerdexam
GIAC

GSEC · Question #40

You are an Intrusion Detection Analyst and the system has alerted you to an Event of Interest (EOI) that appears to be activity generated by a worm. You investigate and find that the network traffic w

The correct answer is A. False Positive. When an IDS generates an alert but investigation confirms no actual attack occurred, the event is a false positive - the system incorrectly classified benign traffic as malicious.

Network Security

Question

You are an Intrusion Detection Analyst and the system has alerted you to an Event of Interest (EOI) that appears to be activity generated by a worm. You investigate and find that the network traffic was normal. How would this type of alert be categorized?

Options

  • AFalse Positive
  • BTrue Negative
  • CTrue Positive
  • DFalse Negative

How the community answered

(19 responses)
  • A
    74% (14)
  • B
    5% (1)
  • C
    5% (1)
  • D
    16% (3)

Why each option

When an IDS generates an alert but investigation confirms no actual attack occurred, the event is a false positive - the system incorrectly classified benign traffic as malicious.

AFalse PositiveCorrect

A false positive occurs when an intrusion detection system fires an alert indicating malicious activity that does not actually exist. In this scenario, the system alerted on traffic resembling a worm signature, but investigation revealed the traffic was entirely normal, meaning the detection was an erroneous alarm with no underlying real threat.

BTrue Negative

A true negative occurs when no alert fires and no attack is present; this scenario involves an alert that was generated, so it cannot be classified as a true negative.

CTrue Positive

A true positive requires both an alert firing and a confirmed real attack; since investigation showed normal traffic with no actual worm, the alert does not correspond to a genuine incident.

DFalse Negative

A false negative occurs when a real attack takes place but the IDS generates no alert; here an alert was generated (even if incorrectly), which is the opposite condition of a false negative.

Concept tested: IDS alert classification - false positive vs other outcomes

Source: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-94.pdf

Topics

#IDS#false positive#alert categorization#intrusion detection

Community Discussion

No community discussion yet for this question.

Full GSEC Practice