Courseiva
mediumMultiple Choice

200-201 Practice Question: A security team implements a network-based IPS

A security team implements a network-based IPS. During testing, they find that legitimate traffic is frequently blocked. Which tuning approach should they prioritize?

⚠ Common exam trap

Cisco often tests the distinction between tuning signatures (which addresses false positives directly) versus changing operational modes or sensitivity levels, which are broader, less precise adjustments that can introduce new risks.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Disable or modify signatures causing false positives.

False positives occur when IPS signatures incorrectly match legitimate traffic. The most direct and effective tuning approach is to disable or modify the specific signatures causing the false positives, which reduces unnecessary blocking without compromising overall security posture.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Change the IPS to fail-open mode.

    Why it's wrong here

    Fail-open lets traffic bypass inspection entirely when the sensor fails, which does nothing to stop legitimate traffic being blocked while the IPS is healthy. Fail-open is the right design for availability-critical inline links, but the fault here is signature accuracy, not device failure.

  • ✗

    Increase the number of IPS sensors.

    Why it's wrong here

    Adding sensors extends inspection coverage across more network segments; it does not change which signatures fire, so the false positives persist. More sensors suit scaling throughput or covering additional links, whereas blocking legitimate traffic requires tuning the signatures or exceptions on the existing device.

  • ✓

    Disable or modify signatures causing false positives.

    Why this is correct

    Modifying or disabling signatures that trigger on legitimate traffic directly reduces false positives, which caused the over-blocking described. Signature-based IPS engines match known patterns, so tuning those specific rules preserves detection of genuine threats while restoring legitimate flows. This satisfies the stem's constraint of frequent blocking of valid traffic.

  • ✗

    Reduce the IPS sensitivity level to lower.

    Why it's wrong here

    Lowering sensitivity to its minimum suppresses detection broadly, so genuine attacks pass alongside the false positives. Sensitivity tuning is legitimate when a specific signature is over-triggering, but here legitimate traffic is blocked across the board, which calls for identifying and exempting the offending signatures.

About these practice questions

This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.