a) What is precision in an IDS?
b) What are false positives, and why are they bad?
c) What are false negatives, and why are they bad?
d) How can tuning reduce the number of false positives?
e) What does an IDS do if it cannot process all of the packets it receives?
f) What may happen if a system runs out of storage space?
g) Why is limiting the size of log files necessary but unfortunate?

