Courseiva
mediumMultiple ChoiceObjective-mapped

200-201 Practice Question: A Cisco Firepower sensor is generating an alert…

A Cisco Firepower sensor is generating an alert for a known benign application. The analyst has verified it is a false positive. What is the first step to suppress this alert?

⚠ Common exam trap

Cisco often tests the distinction between preprocessor-level suppression (NAP exceptions) and rule-level suppression (disabling rules), where candidates mistakenly choose to disable the rule globally instead of creating a targeted exception.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Create a network analysis policy exception.

A network analysis policy (NAP) exception is the correct first step because it allows you to suppress alerts for specific benign applications without affecting the overall detection posture. In Cisco Firepower, NAP exceptions are applied before intrusion rules are evaluated, so they can filter out known false positives at the preprocessor level, preventing the rule from even triggering. This is more efficient than modifying the intrusion rule itself, as it avoids disabling detection for other traffic.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Create a network analysis policy exception.

    Why this is correct

    This suppresses the alert for the specific benign traffic without affecting other detections.

  • Increase the severity threshold.

    Why it's wrong here

    Increasing threshold may not suppress the alert if it still meets higher severity.

  • Submit a false positive report to Talos.

    Why it's wrong here

    This is a long-term action, not the immediate first step.

  • Disable the intrusion rule globally.

    Why it's wrong here

    Disabling globally removes detection for all traffic, which is too drastic.

About these practice questions

Courseiva writes every 200-201 question from scratch — 979 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.