mediumMultiple Choice
200-201 Practice Question: A network intrusion detection system (NIDS)…
A network intrusion detection system (NIDS) generates an alert for a known exploit against a web server. The analyst verifies that the server is patched. What is the next best step?
⚠ Common exam trap
The trap here is assuming that a patched server means the alert is a false positive and can be dismissed or tuned out, when in fact the alert indicates an attempt that must be investigated to confirm no compromise occurred.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Investigate if the exploit was actually attempted
The alert indicates a known exploit signature was triggered against the web server. Even though the server is patched, the NIDS alert means the exploit attempt was observed on the network. The next best step is to investigate whether the exploit was actually attempted, because the patch may have blocked it, but the attempt itself is still a security event that warrants investigation. This aligns with the incident response process: verify, contain, and remediate. Dismissing or tuning without investigation could miss a real attack or a compromised system.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Reconfigure the NIDS to block the traffic
Why it's wrong here
A NIDS is passive and cannot block traffic; reconfiguring it to do so changes its role rather than resolving the alert. Blocking is tempting because containment feels decisive, and an inline IPS would be the right control when active prevention of confirmed malicious traffic is genuinely required.
- ✗
Tune the signature to ignore the server
Why it's wrong here
Suppressing the signature for that host hides future genuine exploitation attempts against it, not just this benign alert. Tuning is tempting because signature noise is common, and excluding a host would be correct if the signature reliably misfired on that host's legitimate traffic.
- ✗
Dismiss the alert as a false positive
Why it's wrong here
The alert fired on real exploit traffic matching a known signature; the server being patched means the attempt failed, not that detection was erroneous. Dismissing is tempting because patched systems resist the exploit, and it would be correct if the traffic were benign rather than an actual attack.
- ✓
Investigate if the exploit was actually attempted
Why this is correct
A patched server cannot be exploited, so the alert may be a false positive or a probe. Confirming whether the exploit traffic actually reached and was attempted against the host distinguishes benign scanning from genuine attack activity before escalation or closure.
Go deeper
Related to this question
About these practice questions
One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.