An IDS signature matches on a specific exploit payload, but the analyst confirms the target system runs a patched OS where the vulnerability does not exist. This alert is classified as:
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — d is correct because the signature fired (positive detection) but the vulnerability does not exist on the target, meaning no actual attack succeeded — the alert is a false positive. A is wrong because a true positive would require that a real, successful attack occurred.
Full explanation below image
Full Explanation
D is correct because the signature fired (positive detection) but the vulnerability does not exist on the target, meaning no actual attack succeeded — the alert is a false positive. A is wrong because a true positive would require that a real, successful attack occurred. B is wrong because a false negative means the IDS missed an actual attack. C is wrong because a true negative means no attack occurred and no alert fired.