A field engineer keeps seeing IPS alerts fire and block a legitimate operational polling protocol traveling between the NOC and a substation switching station. The sensor protecting that link covers a broad set of signatures. Which change addresses the false positive with the least collateral impact on the rest of the substation's protection?
Select an answer to reveal the explanation.
Short Explanation
It's like turning off one smoke detector that keeps chirping instead of pulling the whole fire alarm panel off the wall. Tune the one signature that's misfiring and leave the rest of the sensor doing its job.
Full Explanation
IPS sensors let an administrator override the action of an individual signature or exempt it for specific traffic, so a single misbehaving match can be handled without touching anything else the sensor protects. That precision is exactly what a false positive on a known-legitimate protocol calls for. Disabling the entire sensor removes every other signature's protection from the link, not just the one that misfired — a heavy price for one noisy alert. Removing the security profile from the policy entirely goes even further, stripping all content inspection from substation traffic and leaving the segment far more exposed than before. Raising the overall severity threshold is a blunt instrument too: it can silence genuinely dangerous lower-severity signatures elsewhere in the sensor while offering no guarantee it excludes only the one signature causing trouble. A caveat worth remembering: an exemption should be scoped as tightly as possible, ideally to the specific source or destination generating the false positive, so it doesn't quietly open a wider hole than intended. To confirm the tuning worked, watch the IPS log after the change — the false alert for that signature should stop appearing while other signatures on the same sensor keep logging normally.