A network administrator is reviewing server alerts because of reports of network slowness. The administrator confirms that an alert was an actual security incident. What is the security alert classification of this type of scenario?
- true negative
- false negative
- false positive
- true positive
Explanation & Hint:
The security alert classification for this scenario, where an alert was confirmed to be an actual security incident, is a true positive. A true positive occurs when the security system correctly identifies a genuine threat or incident. Here are all the classifications for clarity:
|