hardMultiple Choice
200-201 Practice Question: A Security Operations Center (SOC) uses Security…
A Security Operations Center (SOC) uses Security Information and Event Management (SIEM) with event correlation. Analysts notice that alerts for a specific malware signature have decreased sharply after a new firewall rule was deployed. However, endpoint scans still show infections on several hosts. What is the most likely explanation for the decrease in SIEM alerts?
⚠ Common exam trap
Cisco often tests the concept that blocking C2 traffic reduces network alerts but does not remediate endpoint infections, leading candidates to mistakenly think the firewall rule eliminated the malware entirely.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The firewall rule blocks the malware's C2 traffic, so SIEM no longer receives network alerts, but endpoint infections persist
The firewall rule specifically blocks command-and-control (C2) traffic, which is the network communication channel the malware uses to send data or receive instructions. Since the SIEM relies on network-based alerts (e.g., from intrusion detection systems or firewall logs) to detect this traffic, blocking the C2 traffic eliminates those network alerts. However, the malware remains on the endpoints because the firewall does not remove the infection; it only prevents outbound communication, so endpoint scans still detect the malware files or processes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The firewall rule blocks the malware's C2 traffic, so SIEM no longer receives network alerts, but endpoint infections persist
Why this is correct
The firewall rule blocks command-and-control traffic, so the SIEM's network-based correlation rules stop firing. Endpoint scans still detect the malware because the infection persists locally; only its outbound channel is severed, not the implant itself.
- ✗
The SIEM correlation rules were accidentally disabled during the firewall update
Why it's wrong here
Disabling correlation rules would suppress all signatures, not one, and the firewall change would not touch SIEM configuration. Correlation rules are correctly disabled during tuning or maintenance. The signature-specific drop with ongoing endpoint infections points to the firewall rule blocking the traffic the signature detected.
- ✗
The SIEM is not receiving logs from the endpoint detection and response (EDR) tool
Why it's wrong here
The firewall rule filters network traffic, not EDR telemetry, so EDR logs would still reach the SIEM; this does not explain the timing. It is tempting because missing log sources genuinely cause alert gaps, but here the drop correlates with the firewall change while endpoint scans still detect infections.
- ✗
The malware has mutated into a different variant that evades detection
Why it's wrong here
Mutation would reduce signature matches, yet the alert drop coincides exactly with the firewall rule deployment, and endpoint scans still identify the same signature on hosts. It is tempting because polymorphic malware does evade detection, but the timing and unchanged endpoint results point to network telemetry loss.
Go deeper
Related to this question
About these practice questions
One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.