QuestionQ49

Intrusion Detection and Prevention (IDP)

Which two methods can help reduce false positives for an IDP rule?

Choose two
Explanation

Removing an attack object prevents that signature from matching in the IDP rule. An exempt rule can exclude known false-positive attack objects or specified traffic from IDP detection, preventing unnecessary alarms. Juniper documents exempt rulebases specifically for excluding known false positives.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!