When analyzing the IDS logs, the system administrator noticed an alert was logged when the external router was accessed from the administrator’s Computer to update the router configuration. What type of an alert is this?
from the reponse of hasib125 - V10 Q213 -
D. False positive
True Positive - IDS referring a behavior as an attack, in real life it is
True Negative - IDS referring a behavior not an attack and in real life it is not
False Positive - IDS referring a behavior as an attack, in real life it is not
False Negative - IDS referring a behavior not an attack, but in real life is an attack
This is a poorly worded question. The best answer is a Benign Positive, since the alert is doing a true detection, but the activity isn't malicious. Unfortunately EC-Council does not list "Benign Positive" as one of the answers on the pick list. According to NIST SP 800-86 pages 6-13 and C-1, a benign positive is a type of false positive. See also https://csrc.nist.gov/glossary/term/false_positive. So the best answer of the ones listed is D. False positive.
False Positive (No attack - Alert). The IDS is doing its job correctly but there is no attack in this case because it was the administrator's legitimate action that triggered the alert.
False Positive (No attack - Alert). The ISD is doing its job correctly but there is no attack in this case because it was the administrator's legitimate action that triggered the alert.
the C option is Correct :True Positive
https://developers.google.com/machine-learning/crash-course/classification/true-false-positive-negative#:~:text=Similarly%2C%20a%20true%20negative%20is,incorrectly%20predicts%20the%20negative%20class.
This is a true positive alert, as the IDS correctly identified an actual security event that occurred. The event was the administrator accessing the external router to update the configuration, which triggered the IDS alert.
upvoted 2 times
...
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
jeremy13
Highly Voted 1 year, 5 months agoboog
Highly Voted 1 year, 7 months agoinsaniunt
Most Recent 11 months ago[Removed]
11 months, 1 week agoEnidV
1 year, 3 months agoEnidV
1 year, 3 months agoVincent_Lu
1 year, 5 months agovictorfs
1 year, 6 months agoMuli_70
1 year, 6 months agosausageman
1 year, 7 months agoeli117
1 year, 7 months ago