Which IDS Performance Trend Causes Greatest Concern?

Security Monitoring & Analysis
Answer Correct answer: A — An increase in false negatives represents the greatest concern because it indicates the IDS is failing to detect actual malicious activity or attacks.

Which of the following trends would be of GREATEST concern when reviewing the performance of an organization's intrusion detection systems (IDSs)?

  1. Increase in false negatives Correct Answer
  2. Increase in false positives
  3. Decrease in false positives
  4. Decrease in false negatives

Community Votes

A
100%

100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests understanding of IDS error types and prioritizes missed detections over false alerts in risk management decisions.

CISM candidates must recognize that missing actual attacks poses a higher risk than alert fatigue. Community consensus confirms that rising false negatives represent the most critical threat to organizational security.

Selecting false positives due to confusion over terminology or overestimating the operational impact of alert fatigue compared to undetected breaches.

Community Discussion (3 comments)

isaphiltrick 👍 9 Selected: A
False negatives occur when the IDS does not alert on an attack or malicious activity that is present. This is much more of a concern than false positives--at least the IDS is detecting something with those.
Saisharan 👍 5
False negatives happen when the IDS fails to detect actual malicious activity, So Option A
Bl1024 👍 1 Selected: B
B - False Positive means that the IDS failed to identify a true incident, False Negative is actually a false identification of something that is legit.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

False negatives indicate the IDS failed to detect real malicious activity. In a CISM context, missing an actual breach directly impacts confidentiality, integrity, and availability, making it the highest priority to address. Organizations must tune detection rules and update signatures to minimize these gaps before focusing on other metrics.

Why the Other Options Are Wrong

Increasing false positives causes analyst fatigue but still triggers necessary investigations into potential incidents. Decreasing false positives simply reduces operational noise without improving detection coverage. Decreasing false negatives is the desired security outcome, so viewing it as a concern contradicts fundamental risk management principles.

Community Comment Notes

Users consistently validate option A, emphasizing that undetected threats far outweigh nuisance alerts in business impact assessments. One comment incorrectly swaps the definitions of false positives and negatives, which highlights a common trap for test-takers unfamiliar with security telemetry terminology. Always verify your baseline definitions before selecting performance trend answers.

Official Reference

Exam Strategy

Focus on risk-based decision making rather than technical tuning when evaluating security controls. When comparing metric trends, always prioritize options that prevent undetected compromise over those that merely improve operational efficiency or reduce noise.

Frequently Asked Questions

Why is increasing false positives less concerning than false negatives?

False positives trigger investigations but do not allow breaches to go unnoticed, whereas false negatives miss actual attacks entirely, creating direct security exposure.

How should CISM candidates interpret IDS performance trends?

Focus on risk mitigation over operational efficiency; reducing missed detections takes priority over reducing alert noise for optimal security posture.

Related Analysis

Practice All CISM Questions

Access 400 questions with complete answers and detailed explanations.

View Full CISM Practice Test →

← Back to CISM Study Guide