A security operations center (SOC) receives an alert from its intrusion detection system (IDS) about a possible SQL injection attack against a web server. The SOC analyst reviews the IDS signature and sees that it triggered on a request containing the string 'OR 1=1'. However, the web application logs show that the request was blocked by a web application firewall (WAF) and returned a 403 error. Which of the following BEST describes the nature of this alert?
The IDS correctly identified a SQL injection attempt (true positive). The WAF then blocked the request, as evidenced by the 403 error. This means the attack was detected and prevented. The alert is a true positive because the IDS accurately flagged malicious activity, even though the attack was stopped. The SOC should still investigate the source and consider tuning.
Why this answer
The IDS correctly identified a SQL injection attempt, making it a true positive. The WAF then blocked the request, as shown by the 403 error, so the attack was prevented. This is a true positive detection with successful mitigation.
It is not a false positive because the traffic was malicious, and not a false negative because the IDS did alert. The SOC should investigate the source and consider whether the IDS signature needs tuning to reduce noise.
Exam trap
The trap here is equating a true positive alert with a successful attack, but a true positive can occur even when the attack is blocked by another control.