Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Cisco Exam 300-215 Topic 5 Question 72 Discussion

Actual exam question for Cisco's 300-215 exam
Question #: 72
Topic #: 5
[All 300-215 Questions]

Refer to the exhibit.

A company that uses only the Unix platform implemented an intrusion detection system. After the initial configuration, the number of alerts is overwhelming, and an engineer needs to analyze and classify the alerts. The highest number of alerts were generated from the signature shown in the exhibit. Which classification should the engineer assign to this event?

Show Suggested Answer Hide Answer
Suggested Answer: C

Comments

Alita
1 days ago
Hmm, let's think this through. Based on the information provided, it seems like the high number of alerts is a problem, so the engineer needs to classify them correctly. I'm leaning towards D) True Positive alert, since that seems to be the right classification for a legitimate security event that the system is detecting.
upvoted 0 times
...
Caitlin
3 days ago
Wow, this question is really tricky! I'm not sure I understand the difference between all these 'false' and 'true' alert classifications. Can someone help me out here?
upvoted 0 times
...

Save Cancel