D4 ยท Operations

What is a false positive and false negative in security?

๐Ÿ”ด False positive: legitimate activity flagged as malicious. Causes alert fatigue.
๐Ÿ”ต False negative: malicious activity not detected. More dangerous โ€” missed attack.
Tuning IDS/IPS reduces false positives. Too sensitive = false positives. Too lenient = false negatives. Both are bad โ€” balance is key. False negatives are more dangerous (undetected attacks).
โ† Back to Glossary Practice Questions โ†’