Which two methods can help reduce false positives for an IDP rule?
Removing an attack object prevents that signature from matching in the IDP rule. An exempt rule can exclude known false-positive attack objects or specified traffic from IDP detection, preventing unnecessary alarms. Juniper documents exempt rulebases specifically for excluding known false positives.
Community Discussion