Courseiva
hardMultiple ChoiceObjective-mapped

200-201 Practice Question: A Security Operations Center (SOC) uses Security…

A Security Operations Center (SOC) uses Security Information and Event Management (SIEM) with event correlation. Analysts notice that alerts for a specific malware signature have decreased sharply after a new firewall rule was deployed. However, endpoint scans still show infections on several hosts. What is the most likely explanation for the decrease in SIEM alerts?

⚠ Common exam trap

Cisco often tests the concept that blocking C2 traffic reduces network alerts but does not remediate endpoint infections, leading candidates to mistakenly think the firewall rule eliminated the malware entirely.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The firewall rule blocks the malware's C2 traffic, so SIEM no longer receives network alerts, but endpoint infections persist

The firewall rule specifically blocks command-and-control (C2) traffic, which is the network communication channel the malware uses to send data or receive instructions. Since the SIEM relies on network-based alerts (e.g., from intrusion detection systems or firewall logs) to detect this traffic, blocking the C2 traffic eliminates those network alerts. However, the malware remains on the endpoints because the firewall does not remove the infection; it only prevents outbound communication, so endpoint scans still detect the malware files or processes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The firewall rule blocks the malware's C2 traffic, so SIEM no longer receives network alerts, but endpoint infections persist

    Why this is correct

    The SIEM relies on network events for that signature; blocking C2 traffic stops the alerts but does not remediate existing infections.

  • The SIEM correlation rules were accidentally disabled during the firewall update

    Why it's wrong here

    There is no evidence of SIEM misconfiguration; the firewall rule change explains the drop in network alerts.

  • The SIEM is not receiving logs from the endpoint detection and response (EDR) tool

    Why it's wrong here

    If EDR logs were missing, alerts would drop for endpoint detections as well, but the scenario only mentions decrease in a specific malware signature, not all alerts.

  • The malware has mutated into a different variant that evades detection

    Why it's wrong here

    If the malware mutated, endpoint scans would likely not detect it either, but they do detect infections.

About these practice questions

One of 979 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.