
642 -531
Leading the way in IT testing and certification tools, www.testking.com
- 10 -
Cisco router but mistakenly enters the wrong password. The IDS cannot distinguish between a
rogue user and the network administrator, and generates an alarm.
Reference: Cisco Courseware p.3-11
QUESTION NO: 2
What is a false negative alarm situation?
A. normal traffic does not cause a signature to fire
B. a signature is fired when offending traffic is not detected
C. normal traffic or a benign action causes the signature to fire
D. a signature is not fired when offending traffic is present
ANSWER: D
Cisco Courseware 3-11
QUESTION NO: 3
A Cisco IDS Sensor has been configured to detect attempts to extract the password file
from Windows 2000 systems. During a security posture assessment, the consultants
attempted to extract the password files from three Windows 2000 servers.
This activity was detected by the Sensor.
What situation has this activity caused?
A. True negative
B. True positive
C. False negative
D. False positive
Answer: B
Explanation:
True positive – is when an IDS generates an alarm for known intrusive activity.
False negative – is when an IDS fails to generates an alarm for known intrusive activity.
False positive - is when an IDS generates an alarm for normal user activity.
Reference: Cisco Secure Intrusion Detection System (Ciscopress) page 55 & 58
Note: True positive –A situation in which a signature is fired properly when offending traffic
is detected. An attack is detected as expected. - Cisco Secure Intrusion Detection System 4
chap 3 page 12
QUESTION NO: 4
Comentarios a estos manuales