Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam 312-50v12 All Questions

View all questions & answers for the 312-50v12 exam

Exam 312-50v12 topic 1 question 98 discussion

Actual exam question from ECCouncil's 312-50v12
Question #: 98
Topic #: 1
[All 312-50v12 Questions]

When analyzing the IDS logs, the system administrator noticed an alert was logged when the external router was accessed from the administrator’s Computer to update the router configuration.
What type of an alert is this?

  • A. False negative
  • B. True negative
  • C. True positive
  • D. False positive
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
jeremy13
Highly Voted 1 year, 5 months ago
Selected Answer: D
from the reponse of hasib125 - V10 Q213 - D. False positive True Positive - IDS referring a behavior as an attack, in real life it is True Negative - IDS referring a behavior not an attack and in real life it is not False Positive - IDS referring a behavior as an attack, in real life it is not False Negative - IDS referring a behavior not an attack, but in real life is an attack
upvoted 10 times
...
boog
Highly Voted 1 year, 7 months ago
D. False Positive Not an attack/intrusion
upvoted 5 times
...
insaniunt
Most Recent 11 months ago
Selected Answer: D
D. False positive
upvoted 1 times
...
[Removed]
11 months, 1 week ago
Selected Answer: D
This is a poorly worded question. The best answer is a Benign Positive, since the alert is doing a true detection, but the activity isn't malicious. Unfortunately EC-Council does not list "Benign Positive" as one of the answers on the pick list. According to NIST SP 800-86 pages 6-13 and C-1, a benign positive is a type of false positive. See also https://csrc.nist.gov/glossary/term/false_positive. So the best answer of the ones listed is D. False positive.
upvoted 1 times
...
EnidV
1 year, 3 months ago
Selected Answer: D
False Positive (No attack - Alert). The IDS is doing its job correctly but there is no attack in this case because it was the administrator's legitimate action that triggered the alert.
upvoted 2 times
...
EnidV
1 year, 3 months ago
Selected Answer: D
False Positive (No attack - Alert). The ISD is doing its job correctly but there is no attack in this case because it was the administrator's legitimate action that triggered the alert.
upvoted 2 times
...
Vincent_Lu
1 year, 5 months ago
Selected Answer: D
D. False positive
upvoted 3 times
...
victorfs
1 year, 6 months ago
Selected Answer: C
C. True positive the IDS correctly identified the access to the external router event
upvoted 1 times
...
Muli_70
1 year, 6 months ago
the C option is Correct :True Positive https://developers.google.com/machine-learning/crash-course/classification/true-false-positive-negative#:~:text=Similarly%2C%20a%20true%20negative%20is,incorrectly%20predicts%20the%20negative%20class.
upvoted 2 times
...
sausageman
1 year, 7 months ago
Selected Answer: D
D. False positive
upvoted 4 times
...
eli117
1 year, 7 months ago
Selected Answer: C
This is a true positive alert, as the IDS correctly identified an actual security event that occurred. The event was the administrator accessing the external router to update the configuration, which triggered the IDS alert.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...