350-701 Network Security Practice Question
A security analyst is investigating a potential intrusion and suspects that the IPS is missing some attacks (false negatives). Which two factors can contribute to false negatives in signature-based IPS? (Choose two.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The attack uses a new exploit for which no signature exists.
False negatives occur when the IPS fails to detect an actual attack. Common causes include outdated signatures, encrypted traffic that cannot be inspected, and evasion techniques like fragmentation or encoding that the IPS cannot reassemble. Also, if the sensor is in passive mode and misses traffic due to asymmetric routing, it can cause false negatives.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The attack uses a new exploit for which no signature exists.
Why this is correct
Correct. Signature-based detection cannot detect unknown attacks without a matching signature.
- ✗
The IPS is in inline mode and blocks malicious traffic.
Why it's wrong here
Incorrect. Blocking is a correct action, not a false negative.
- ✓
The traffic is encrypted and the IPS cannot inspect the payload.
Why this is correct
Correct. Encrypted payloads hide the attack from signature inspection.
- ✗
The signature threshold is set too low.
Why it's wrong here
Incorrect. Low threshold would cause more alerts (false positives), not false negatives.
- ✗
The IPS is configured to drop packets that match a signature.
Why it's wrong here
Incorrect. Dropping would prevent the attack, not cause a false negative.
Quick reference
Asymmetric Encryption Algorithm Comparison
| Algorithm | Key Exchange | Signatures | Equivalent Security Key | Notes |
|---|---|---|---|---|
| RSA-3072 | Yes | Yes | 128-bit | Widely deployed; slow for bulk data |
| ECDSA P-256 | No | Yes | 128-bit | Fast signatures; standard TLS certs |
| ECDH / ECDHE | Yes | No | 128-bit | Perfect forward secrecy in TLS 1.3 |
| DH / DHE | Yes | No | 128-bit (3072-bit key) | Replaced by ECDHE in modern TLS |
| Ed25519 | No | Yes | ~128-bit | SSH keys, modern PKI |
Go deeper
Related to this question
About these practice questions
Courseiva writes every 350-701 question from scratch — 978 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-701 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-701 exam.