According to the CEH IDS/IPS module, false positives occur when legitimate activity is incorrectly flagged as malicious. The most common cause is overly sensitive IDS rules or thresholds.
Option D correctly identifies this issue.
Option A describes the symptom, not the root cause.
Option B is unrelated to IDS alert behavior.
Option C can cause missed detections, not excessive alerts.
CEH recommends proper tuning and baseline profiling.
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit