Correct Answer: A well-chosen base policy, correctly scoped variable sets, appropriate rule states (including Drop and Generate Events where warranted), suppression rules for known-noisy false positives, and thresholds for high-frequency low-severity signatures
Explanation: Effective intrusion policy design combines a suitable base policy, properly scoped variables, tuned rule states, targeted suppression, and thresholds, unlike leaving defaults and variables unreviewed, blanket dropping with no tuning, skipping the base policy entirely, indiscriminate suppression of every rule, or untargeted threshold application.
Correct Answer: A well-chosen base policy, correctly scoped variable sets, appropriate rule states (including Drop and Generate Events where warranted), suppression rules for known-noisy false positives, and thresholds for high-frequency low-severity signatures
Explanation: Effective intrusion policy design combines a suitable base policy, properly scoped variables, tuned rule states, targeted suppression, and thresholds, unlike leaving defaults and variables unreviewed, blanket dropping with no tuning, skipping the base policy entirely, indiscriminate suppression of every rule, or untargeted threshold application.