exam questions

Exam 200-201 All Questions

View all questions & answers for the 200-201 exam

Exam 200-201 topic 1 question 147 discussion

Actual exam question from Cisco's 200-201
Question #: 147
Topic #: 1
[All 200-201 Questions]

An analyst discovers that a legitimate security alert has been dismissed.
Which signature caused this impact on network traffic?

  • A. true negative
  • B. false negative
  • C. false positive
  • D. true positive
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
HarryPotter69
Highly Voted 3 years, 4 months ago
A false negative occurs when the security system (usually a WAF) fails to identify a threat. It produces a “negative” outcome (meaning that no threat has been observed), even though a threat exists. This is the opposite of a false positive alarm, where a system mistakenly identifies legitimate traffic as being hostile. I would answer - false negative
upvoted 25 times
JayPEI
2 years, 7 months ago
identifie nothing means false positive
upvoted 1 times
MartinRB
1 year, 11 months ago
false positive means, alert raised by mistake, no threat is there, example a SPAM vs malicious email, SPAM is a false positive.
upvoted 1 times
...
...
...
Hellome123
Most Recent 2 weeks, 3 days ago
Selected Answer: B
False Positive - Incorrectly classified as positive True Positive - Correctly classified as positive False Negative - Incorrectly classified as Negative True Negative - Correctly classified as Negative
upvoted 1 times
...
d503c75
4 months, 1 week ago
True = Attack False = No Attack Positive = Alert Negative = No Alert Sooo the answer is A -> There's an attack, but no alert.
upvoted 1 times
d503c75
4 months ago
Sorry, correcting: FP -> - Alert -- NoAttack FN -> - NoAlert -- Attack TP --> Attack - Alert TN --> NoAttack - NoAlert The answer is FN. Option B
upvoted 1 times
...
...
sheyshey
1 year, 1 month ago
Selected Answer: B
should be B
upvoted 2 times
...
Faio
1 year, 4 months ago
The answer is B. false negative.
upvoted 1 times
...
SecurityGuy
1 year, 5 months ago
Selected Answer: B
False Positive - Incorrectly classified as positive True Positive - Correctly classified as positive False Negative - Incorrectly classified as Negative True Negative - Correctly classified as Negative In this case, the legitimate alert was "incorrectly classified as negative".
upvoted 1 times
...
slippery31
1 year, 6 months ago
False Negative
upvoted 1 times
...
Topsecret
1 year, 6 months ago
Selected Answer: C
The correct answer is C. false positive. When an analyst discovers that a legitimate security alert has been dismissed, it indicates a false positive. A false positive occurs when a security system or tool generates an alert or indicates a security incident that is not actually malicious or threatening. In this case, the dismissed alert was mistakenly considered as a non-threatening event, leading to the legitimate security alert being ignored or overlooked.
upvoted 1 times
ethhacker
1 year, 4 months ago
Wrong. Answer is false negative. Attack not detected by system. End of discussion
upvoted 2 times
...
...
Swordfishtaco
1 year, 6 months ago
false negative =no alarm with a true attack.
upvoted 1 times
...
Isuckatexams
1 year, 7 months ago
Selected Answer: D
A True Positive generated the Alert. The alert was dismissed
upvoted 1 times
...
CrazyD1337
1 year, 7 months ago
a false negative occurs when a system fails to identify a threat producing a negative outcome even though a threat exists... the system didn't fail to identify a threat. a false positive occurs when a system mistakenly identifies legitimate traffic as being hostile... the system didn't mistakenly identify legitimate traffic as being hostile, it's a legitimate security alert. a true negative security alert refers to a situation where an alert has not been generated when a specific activity has occured (i.e. a threat)... the system didn't fail to generate an alert. it was dismissed. a true positive security alert refers to a legitimate attack that triggers an alarm.. a legitimate alert was generated... and the only 'thing' (signature) that could cause this, would be a true positive. an analyst discovers that a LEGITIMATE security alert (true positive) has been dismissed... someone dismissed a legitimate alert... imo, A, B and C are incorrect. I'm going with D.
upvoted 1 times
...
Mack279
1 year, 7 months ago
Put the question this way, there is a legit attack/threat but the system did not see it as a threat. Answer is B, false negative.
upvoted 1 times
...
alhamry
1 year, 8 months ago
negative means: there is no alert. false negative means: the "no alert" is false > a legitimate security alert has been dismissed therefore the correct answer is B
upvoted 1 times
alhamry
1 year, 8 months ago
to understand it, think like that: - positive: there is alert triggered: 1- true positive: true alert > there is a threat 2- false positive: false alert > no actual threat - negative: there is no alert triggered: 1- true negative: true "no alert" > there is no threat 2- false negative: false "no alert" > there is a threat
upvoted 3 times
...
...
drdecker100
1 year, 11 months ago
Selected Answer: B
The correct answer is B. A false negative occurs when a security alert is missed or dismissed, allowing malicious traffic to go unnoticed. In this case, the analyst discovered that a legitimate security alert was dismissed, indicating that a threat was present but was not detected by the system. Therefore, the impact on network traffic was a false negative.
upvoted 3 times
...
apebrz
2 years, 3 months ago
I think it D: An analyst discovers that a legitimate security alert (True Positive) has been dismissed (whatever the reason, human fail for example)
upvoted 3 times
...
weganos
2 years, 4 months ago
Selected Answer: B
I agree it's B
upvoted 2 times
...
surforlife
2 years, 6 months ago
Real true then is the opposite negative. Not true is then negative! Answer is B False Negative.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago