mediumMultiple ChoiceObjective-mapped
200-201 Practice Question: A Cisco Firepower sensor is generating an alert…
A Cisco Firepower sensor is generating an alert for a known benign application. The analyst has verified it is a false positive. What is the first step to suppress this alert?
⚠ Common exam trap
Cisco often tests the distinction between preprocessor-level suppression (NAP exceptions) and rule-level suppression (disabling rules), where candidates mistakenly choose to disable the rule globally instead of creating a targeted exception.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a network analysis policy exception.
A network analysis policy (NAP) exception is the correct first step because it allows you to suppress alerts for specific benign applications without affecting the overall detection posture. In Cisco Firepower, NAP exceptions are applied before intrusion rules are evaluated, so they can filter out known false positives at the preprocessor level, preventing the rule from even triggering. This is more efficient than modifying the intrusion rule itself, as it avoids disabling detection for other traffic.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create a network analysis policy exception.
Why this is correct
This suppresses the alert for the specific benign traffic without affecting other detections.
- ✗
Increase the severity threshold.
Why it's wrong here
Increasing threshold may not suppress the alert if it still meets higher severity.
- ✗
Submit a false positive report to Talos.
Why it's wrong here
This is a long-term action, not the immediate first step.
- ✗
Disable the intrusion rule globally.
Why it's wrong here
Disabling globally removes detection for all traffic, which is too drastic.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-201 question from scratch — 979 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.