SECOPS-PRO · Question #76
A Security Operations Center (SOC) analyst is reviewing alerts generated by a Palo Alto Networks Next-Generation Firewall (NGFW) configured with Threat Prevention. An alert is triggered for an…
The correct answer is C. False Positive; The alert was generated for legitimate traffic. Suppress the alert and create an. This scenario describes a False Positive. The alert was triggered by legitimate activity that was mistakenly identified as malicious. The correct action is to suppress the alert for this specific legitimate pattern (e.g., by creating an exclusion policy or refining the…
Question
A Security Operations Center (SOC) analyst is reviewing alerts generated by a Palo Alto Networks Next-Generation Firewall (NGFW) configured with Threat Prevention. An alert is triggered for an alleged 'C2 beaconing' activity from an internal host to an external IP address. Upon investigation, the analyst discovers the external IP belongs to a legitimate cloud-based productivity suite, and the traffic is standard API communication. What is the most accurate classification of this alert, and what immediate action should be taken?
Options
- AFalse Negative; The firewall missed a true C2 connection. Reconfigure the firewall to be more
- BTrue Positive; This is a confirmed C2 connection. Isolate the host immediately and initiate incident
- CFalse Positive; The alert was generated for legitimate traffic. Suppress the alert and create an
- DTrue Negative; The firewall correctly identified benign traffic. No action is required.
- EFalse Positive; The alert was generated for legitimate traffic. Report to vendor and disable the C2
How the community answered
(29 responses)- B14% (4)
- C76% (22)
- D7% (2)
- E3% (1)
Explanation
This scenario describes a False Positive. The alert was triggered by legitimate activity that was mistakenly identified as malicious. The correct action is to suppress the alert for this specific legitimate pattern (e.g., by creating an exclusion policy or refining the signature application) to reduce alert fatigue without compromising security for actual threats. Disabling the C2 signature globally (Option E) would be a severe overreaction and could lead to true negatives, allowing actual C2 traffic to pass unnoticed.
Topics
Community Discussion
No community discussion yet for this question.