mediumMultiple ChoiceObjective-mapped
200-201 Practice Question: A security analyst is reviewing logs from a Cisco…
A security analyst is reviewing logs from a Cisco Firepower Management Center and notices that many legitimate SSL connections are being blocked by the intrusion policy. Which configuration change should the analyst make to reduce false positives without compromising security?
⚠ Common exam trap
Cisco often tests the distinction between modifying intrusion policy rules versus using network analysis policy exceptions, tempting candidates to choose a global or severity-based change instead of the targeted exception that preserves security for other traffic.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Add the affected servers to a network analysis policy exception.
Adding the affected servers to a network analysis policy (NAP) exception allows the Firepower system to bypass intrusion inspection for traffic to and from those specific hosts while still performing SSL decryption and other security checks. This reduces false positives from legitimate SSL connections without completely disabling SSL inspection or weakening the overall security posture.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Increase the severity threshold for SSL-related rules.
Why it's wrong here
Increasing severity threshold may not be possible or effective in reducing false positives.
- ✓
Add the affected servers to a network analysis policy exception.
Why this is correct
This allows specific traffic to bypass inspection while keeping security for others.
- ✗
Change the intrusion policy to "Connectivity Over Security".
Why it's wrong here
This is a less secure profile that allows more traffic but reduces overall security.
- ✗
Disable SSL inspection globally.
Why it's wrong here
Disabling globally removes protection for all SSL traffic, compromising security.
Go deeper
Related to this question
About these practice questions
One of 979 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.