nerdexam
Palo_Alto_Networks

PCCET · Question #79

In an IDS/IPS, which type of alarm occurs when legitimate traffic is improperly identified as malicious traffic?

The correct answer is A. False-positive. In anti-malware, a false positive incorrectly identifies a legitimate file or application as malware. A false negative incorrectly identifies malware as a legitimate file or application. In intrusion detection, a false positive incorrectly identifies legitimate traffic as a…

Submitted by jaden.t· Apr 18, 2026Security Operations (SOC)

Question

In an IDS/IPS, which type of alarm occurs when legitimate traffic is improperly identified as malicious traffic?

Options

  • AFalse-positive
  • BTrue-negative
  • CFalse-negative
  • DTrue-positive

How the community answered

(60 responses)
  • A
    88% (53)
  • B
    3% (2)
  • C
    2% (1)
  • D
    7% (4)

Explanation

In anti-malware, a false positive incorrectly identifies a legitimate file or application as malware. A false negative incorrectly identifies malware as a legitimate file or application. In intrusion detection, a false positive incorrectly identifies legitimate traffic as a threat, and a false negative incorrectly identifies a threat as legitimate traffic.

Topics

#IDS/IPS#Security Monitoring#False Positive#Alerting

Community Discussion

No community discussion yet for this question.

Full PCCET Practice