QuestionQ60

Security Operations

What would result in an unusually large number of false-positive alerts?

  • A Post-breach recovery plan is well defined.
  • B User privilege is configured to be strict.
  • C Device is unable to receive an IP address.
  • D Traffic match criteria is too generalized.
Explanation

Overly generalized traffic-matching criteria are not specific enough to distinguish malicious activity from normal traffic, so they generate many alerts for benign events.

Community Discussion

No comments yet. Be the first to start the discussion!