Which event would generate a false positive alert?
A.
A firewall categorizes a benign application as malicious.
B.
A network sensor is unable to identify a custom application.
C.
A network tunnel accidentally switches from one route to another.
D.
An employee attempts to access an unauthorized application.
The Answer Is:
A
This question includes an explanation.
Explanation:
A false positive occurs when a security control identifies normal or benign activity as malicious. If a firewall categorizes a benign application as malicious, it generates an alert or enforcement decision that incorrectly indicates threat activity. That is the definition of a false positive. A network sensor being unable to identify a custom application is a visibility or classification limitation, but not necessarily a false positive unless it incorrectly labels the traffic as malicious. A tunnel switching routes may be a network event or availability issue. An employee attempting to access an unauthorized application may be a true policy violation, even if it is not malicious. False positives matter because they consume analyst time, reduce trust in alerts, and contribute to alert fatigue. SOC teams reduce false positives by tuning rules, improving context, using baselines, adding allow lists carefully, and refining detection logic. Reference/topics: Security Operations 6.4, false positive and false negative alerts; Network Security 3.2, firewall policy enforcement.
Apprentice PDF/Engine
Printable Format
Value of Money
100% Pass Assurance
Verified Answers
Researched by Industry Experts
Based on Real Exams Scenarios
100% Real Questions
Get 65% Discount on All Products,
Use Coupon: "ac4s65"