Courseiva
mediumMultiple Choice

200-201 Practice Question: A network intrusion detection system (NIDS)…

A network intrusion detection system (NIDS) generates an alert for a known exploit against a web server. The analyst verifies that the server is patched. What is the next best step?

⚠ Common exam trap

The trap here is assuming that a patched server means the alert is a false positive and can be dismissed or tuned out, when in fact the alert indicates an attempt that must be investigated to confirm no compromise occurred.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Investigate if the exploit was actually attempted

The alert indicates a known exploit signature was triggered against the web server. Even though the server is patched, the NIDS alert means the exploit attempt was observed on the network. The next best step is to investigate whether the exploit was actually attempted, because the patch may have blocked it, but the attempt itself is still a security event that warrants investigation. This aligns with the incident response process: verify, contain, and remediate. Dismissing or tuning without investigation could miss a real attack or a compromised system.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Reconfigure the NIDS to block the traffic

    Why it's wrong here

    A NIDS is passive and cannot block traffic; reconfiguring it to do so changes its role rather than resolving the alert. Blocking is tempting because containment feels decisive, and an inline IPS would be the right control when active prevention of confirmed malicious traffic is genuinely required.

  • ✗

    Tune the signature to ignore the server

    Why it's wrong here

    Suppressing the signature for that host hides future genuine exploitation attempts against it, not just this benign alert. Tuning is tempting because signature noise is common, and excluding a host would be correct if the signature reliably misfired on that host's legitimate traffic.

  • ✗

    Dismiss the alert as a false positive

    Why it's wrong here

    The alert fired on real exploit traffic matching a known signature; the server being patched means the attempt failed, not that detection was erroneous. Dismissing is tempting because patched systems resist the exploit, and it would be correct if the traffic were benign rather than an actual attack.

  • ✓

    Investigate if the exploit was actually attempted

    Why this is correct

    A patched server cannot be exploited, so the alert may be a false positive or a probe. Confirming whether the exploit traffic actually reached and was attempted against the host distinguishes benign scanning from genuine attack activity before escalation or closure.

About these practice questions

One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.