A SOC analyst receives an alert from the SIEM indicating a high volume of outbound traffic from a single workstation to an external IP address on port 22. Upon investigation, the analyst finds the workstation is used by a developer who frequently transfers large files to a remote server via SCP. What is the most appropriate classification for this alert?
A false positive occurs when a security control incorrectly flags benign, authorized activity as malicious. In this case, the SIEM generated an alert for legitimate SCP transfers, meaning the rule triggered on normal administrative behavior rather than an actual security incident.
Why this answer
The alert is triggered by legitimate administrative activity (SCP file transfer), so it is a false positive. The analyst should tune the SIEM to reduce similar alerts.