A Suricata IDS rule fires on traffic between two internal hosts. The signature matches a known SMB exploit. The analyst confirms both hosts are fully patched. What should the analyst conclude?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — d is correct because patching status does not guarantee immunity — exploits may bypass patches, patches may not have applied correctly, or this could indicate lateral movement reconnaissance. The alert warrants investigation, not dismissal.
Full explanation below image
Full Explanation
D is correct because patching status does not guarantee immunity — exploits may bypass patches, patches may not have applied correctly, or this could indicate lateral movement reconnaissance. The alert warrants investigation, not dismissal. A is wrong because permanently suppressing without investigation could mask real incidents. C is wrong because deleting the rule removes detection capability without evidence the rule is wrong. B is wrong because SMB traffic in enterprise environments is typically not TLS-encrypted in a way that prevents Suricata signature matching.