QuestionQ14

Incident Response Techniques

Question Image

Refer to the exhibit. A company using only the Unix platform has implemented an intrusion detection system. After the initial configuration, the alert volume is overwhelming, and an engineer must analyze and classify the alerts. The largest number of alerts was generated by the signature shown in the exhibit.

Which classification should the engineer assign to this event?

  • A True Negative alert
  • B False Negative alert
  • C False Positive alert
  • D True Positive alert
Explanation

The signature is for a Unicode directory-traversal attempt against Microsoft IIS. In an environment that uses only Unix platforms, this IIS-specific event is not a valid threat to the monitored hosts, so the alert is a false positive.

Community Discussion

No comments yet. Be the first to start the discussion!