A county SOC sees two port-scan notables after the same night: one source is the city's authorized vulnerability scanner during the published window, and the other is an unknown external host. How should the analyst disposition them?
Select an answer to reveal the explanation.
Short Explanation
Think fire inspector versus burglar jiggling the same doors. The city's own scanner is supposed to knock; an unknown host doing the same thing is not. The analytic was right both times—the disposition follows authorization, not the port-scan label.
Full Explanation
Enterprise Security dispositions classify analytic outcome independently of workflow status. When a correlation search correctly flags a port scan from an authorized civic scanner in its change window, Benign Positive - Suspicious But Expected is the right label because the activity was expected. The same analytic firing on an unknown scanner is True Positive - Suspicious Activity. Treating both as True Positive pages on expected work; treating both as False Positive hides a real attacker and falsely blames the search logic.