200-201 Question 247
Single answerDuring a routine security monitoring task, a cybersecurity analyst observes an alert triggered by the intrusion detection system (IDS). Upon investigation, the analyst confirms that an unauthorized user successfully gained access to a sensitive database and exfiltrated data. How should this alert be classified?
- A
True positive
- B
False positive
- C
True negative
- D
False negative
Show answer and explanation
Correct answer: A
Explanation
A 'true positive' occurs when a security system correctly identifies a real threat or security incident. In this scenario, the IDS triggered an alert that aligned with an actual unauthorized access event, making it a true positive.
- A. Correct.
This is the correct answer because the alert accurately detected a real security incident where unauthorized access and data exfiltration occurred.
- B. Incorrect.
This is incorrect because a false positive refers to an alert that is triggered but no actual security incident occurred.
- C. Incorrect.
This is incorrect because a true negative indicates that no alert was triggered and no security incident occurred, which is not the case here.
- D. Incorrect.
This is incorrect because a false negative refers to a situation where no alert was triggered even though a security incident occurred.