SECOPS-PRO · Question #77
During a routine security audit, it's discovered that a critical server was successfully breached weeks ago by an advanced persistent threat (APT) group. The breach involved sophisticated lateral move
The correct answer is C. False Negative; The security controls failed to detect an actual breach. The challenge is. This is a classic False Negative. The security controls (Cortex XDR, WildFire) failed to detect an actual malicious event (the breach). The primary challenge is to enhance the detection capabilities, which often involves integrating more comprehensive threat intelligence, tuning
Question
During a routine security audit, it's discovered that a critical server was successfully breached weeks ago by an advanced persistent threat (APT) group. The breach involved sophisticated lateral movement and data exfiltration, yet no alerts were generated by the existing security infrastructure, which includes a Palo Alto Networks Cortex XDR endpoint protection platform and a WildFire cloud- based threat analysis service. How would you classify this scenario from the perspective of the security controls, and what is the primary challenge it presents for a SOC?
Options
- ATrue Positive; The controls successfully identified a threat but the SOC failed to respond. The
- BFalse Positive; The controls over-alerted, desensitizing the SOC to the actual threat. The
- CFalse Negative; The security controls failed to detect an actual breach. The challenge is
- DTrue Negative; The controls correctly determined there was no threat. The challenge is validating
- EThis is an unknown state, requiring further investigation to classify. The challenge is lack of
How the community answered
(33 responses)- A3% (1)
- B3% (1)
- C82% (27)
- D9% (3)
- E3% (1)
Explanation
This is a classic False Negative. The security controls (Cortex XDR, WildFire) failed to detect an actual malicious event (the breach). The primary challenge is to enhance the detection capabilities, which often involves integrating more comprehensive threat intelligence, tuning existing detection rules, deploying additional monitoring tools, or improving behavioral analytics to identify sophisticated, stealthy attacks that bypass signature-based or basic anomaly detection.
Topics
Community Discussion
No community discussion yet for this question.