Courseiva
Network SecuritymediumMultiple SelectObjective-mapped

350-701 Network Security Practice Question

A security analyst is investigating a potential intrusion and suspects that the IPS is missing some attacks (false negatives). Which two factors can contribute to false negatives in signature-based IPS? (Choose two.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The attack uses a new exploit for which no signature exists.

False negatives occur when the IPS fails to detect an actual attack. Common causes include outdated signatures, encrypted traffic that cannot be inspected, and evasion techniques like fragmentation or encoding that the IPS cannot reassemble. Also, if the sensor is in passive mode and misses traffic due to asymmetric routing, it can cause false negatives.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The attack uses a new exploit for which no signature exists.

    Why this is correct

    Correct. Signature-based detection cannot detect unknown attacks without a matching signature.

  • The IPS is in inline mode and blocks malicious traffic.

    Why it's wrong here

    Incorrect. Blocking is a correct action, not a false negative.

  • The traffic is encrypted and the IPS cannot inspect the payload.

    Why this is correct

    Correct. Encrypted payloads hide the attack from signature inspection.

  • The signature threshold is set too low.

    Why it's wrong here

    Incorrect. Low threshold would cause more alerts (false positives), not false negatives.

  • The IPS is configured to drop packets that match a signature.

    Why it's wrong here

    Incorrect. Dropping would prevent the attack, not cause a false negative.

Quick reference

Asymmetric Encryption Algorithm Comparison

AlgorithmKey ExchangeSignaturesEquivalent Security KeyNotes
RSA-3072YesYes128-bitWidely deployed; slow for bulk data
ECDSA P-256NoYes128-bitFast signatures; standard TLS certs
ECDH / ECDHEYesNo128-bitPerfect forward secrecy in TLS 1.3
DH / DHEYesNo128-bit (3072-bit key)Replaced by ECDHE in modern TLS
Ed25519NoYes~128-bitSSH keys, modern PKI

About these practice questions

Courseiva writes every 350-701 question from scratch — 978 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-701 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-701 exam.