200-201 Security Policies and Procedures Practice Question
A SOC analyst at Tier 1 receives an alert for a known malware signature. After initial investigation, the analyst finds that the alert is a false positive caused by an outdated signature. What should the analyst do next?
⚠ Common exam trap
200-201 often tests the boundary between triage and response — candidates pick containment or escalation because they sound 'safe,' but the exam expects recognition that a confirmed false positive is closed and documented, not escalated or acted upon.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Close the alert and document the finding
When a Tier 1 analyst determines an alert is a false positive caused by an outdated signature, the correct action is to close the alert and document the finding so the signature can be reviewed and tuned. Escalating or containing would waste resources on a non-incident. Documentation ensures the false positive is tracked and the detection rule can be improved.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Escalate the alert to Tier 2 for further analysis
Why it's wrong here
Escalation is reserved for alerts needing deeper investigation or higher authority; a confirmed false positive from an outdated signature needs signature update or tuning at Tier 1. Tier 2 handles complex or ambiguous incidents. It tempts because escalation is the default when unsure, but here the cause is already identified and benign.
- ✗
Update the signature database on the security tools
Why it's wrong here
Updating signatures is a detection-engineering task owned by signature maintenance, not the Tier 1 triage step for a confirmed false positive. The analyst should tune or suppress the offending rule and document the FP so future alerts are not raised. Signature updates are correct when the database itself is stale, not when a rule misfires.
- ✗
Initiate the containment process
Why it's wrong here
Containment is for confirmed malicious activity; a false positive from an outdated signature requires tuning or suppression, not isolating hosts. Initiating containment on benign traffic disrupts business operations and wastes incident response effort. It tempts because containment is the standard next step once an alert is validated as a true positive.
- ✓
Close the alert and document the finding
Why this is correct
With the alert confirmed as a false positive from an outdated signature, no genuine incident exists, so the analyst closes it and documents the finding. This preserves the audit trail and supports later tuning of the detection signature.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.