hardMultiple ChoiceObjective-mapped
200-201 Practice Question: A Security Operations Center (SOC) uses Security…
A Security Operations Center (SOC) uses Security Information and Event Management (SIEM) with event correlation. Analysts notice that alerts for a specific malware signature have decreased sharply after a new firewall rule was deployed. However, endpoint scans still show infections on several hosts. What is the most likely explanation for the decrease in SIEM alerts?
⚠ Common exam trap
Cisco often tests the concept that blocking C2 traffic reduces network alerts but does not remediate endpoint infections, leading candidates to mistakenly think the firewall rule eliminated the malware entirely.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The firewall rule blocks the malware's C2 traffic, so SIEM no longer receives network alerts, but endpoint infections persist
The firewall rule specifically blocks command-and-control (C2) traffic, which is the network communication channel the malware uses to send data or receive instructions. Since the SIEM relies on network-based alerts (e.g., from intrusion detection systems or firewall logs) to detect this traffic, blocking the C2 traffic eliminates those network alerts. However, the malware remains on the endpoints because the firewall does not remove the infection; it only prevents outbound communication, so endpoint scans still detect the malware files or processes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The firewall rule blocks the malware's C2 traffic, so SIEM no longer receives network alerts, but endpoint infections persist
Why this is correct
The SIEM relies on network events for that signature; blocking C2 traffic stops the alerts but does not remediate existing infections.
- ✗
The SIEM correlation rules were accidentally disabled during the firewall update
Why it's wrong here
There is no evidence of SIEM misconfiguration; the firewall rule change explains the drop in network alerts.
- ✗
The SIEM is not receiving logs from the endpoint detection and response (EDR) tool
Why it's wrong here
If EDR logs were missing, alerts would drop for endpoint detections as well, but the scenario only mentions decrease in a specific malware signature, not all alerts.
- ✗
The malware has mutated into a different variant that evades detection
Why it's wrong here
If the malware mutated, endpoint scans would likely not detect it either, but they do detect infections.
Go deeper
Related to this question
About these practice questions
One of 979 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.