Which two security alert classifications do cybersecurity analysts prefer?
- true positive
- false positive
- true negative
- false negative
Explanation:
- True positives are the desired type of alert. They mean that the rules that generate alerts have worked correctly.
- False positives are not desirable. Although they do not indicate that an undetected exploit has occurred, they are costly because cybersecurity analysts must investigate false alarms; therefore, time is taken away from investigation of alerts that indicate true exploits.
- True negatives are desirable. They indicate that benign normal traffic is correctly ignored, and erroneous alerts are not being issued.
- False negatives are dangerous. They indicate that exploits are not being detected by the security systems that are in place. These incidents could go undetected for a long time, and ongoing data loss and damage could result.
Related exam: Network Defense (NetDef) Course Final Exam Answers
Related exam: Cybersecurity Essentials v3.0 Course Final Exam Answers
