Quiz 9 Question 1 of 20

An IDS in a production environment generates an alert for an inbound connection matching an exploit signature for a service that is not running on the target host. After verification, this is classified as a false positive. What tuning action reduces similar false positives for this specific rule?

Select an answer to reveal the explanation.

Motivation