200-201 Question 244
Single answerA cybersecurity analyst at a Security Operations Center (SOC) is investigating an alert generated by the organization's intrusion detection system (IDS). The alert indicates potential malicious activity involving an internal server, but after reviewing the server logs and network traffic, the analyst determines that no malicious activity occurred. What is this scenario an example of?
- A
False positive
- B
False negative
- C
True positive
- D
True negative
Show answer and explanation
Correct answer: A
Explanation
In this scenario, the IDS generated an alert for what it believed to be malicious activity. However, after investigation, the activity was found to be legitimate and not malicious. This is an example of a false positive, where the security system incorrectly flagged harmless behavior as a threat.
- A. Correct.
This is correct. A false positive occurs when a security system incorrectly identifies legitimate activity as malicious.
- B. Incorrect.
This is incorrect. A false negative occurs when a security system fails to identify actual malicious activity.
- C. Incorrect.
This is incorrect. A true positive occurs when a security system correctly identifies malicious activity.
- D. Incorrect.
This is incorrect. A true negative occurs when a security system correctly identifies legitimate activity as non-malicious.