A false positive is an alert that incorrectly identifies benign activity as malicious. Over time, if an alerting system generates too many false positives, security teams are likely to ignore these alerts, resulting in "alert fatigue." This increases the risk of missing genuine threats. * True positives and true negatives are accurate and should be acted upon. * False negatives are more dangerous because they fail to identify real threats, but they are not "ignored" since they do not trigger alerts.