Courseiva

200-201 Security Policies and Procedures Practice Question

A SOC analyst at Tier 1 receives an alert for a known malware signature. After initial investigation, the analyst finds that the alert is a false positive caused by an outdated signature. What should the analyst do next?

⚠ Common exam trap

200-201 often tests the boundary between triage and response — candidates pick containment or escalation because they sound 'safe,' but the exam expects recognition that a confirmed false positive is closed and documented, not escalated or acted upon.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Close the alert and document the finding

When a Tier 1 analyst determines an alert is a false positive caused by an outdated signature, the correct action is to close the alert and document the finding so the signature can be reviewed and tuned. Escalating or containing would waste resources on a non-incident. Documentation ensures the false positive is tracked and the detection rule can be improved.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Escalate the alert to Tier 2 for further analysis

    Why it's wrong here

    Escalation is reserved for alerts needing deeper investigation or higher authority; a confirmed false positive from an outdated signature needs signature update or tuning at Tier 1. Tier 2 handles complex or ambiguous incidents. It tempts because escalation is the default when unsure, but here the cause is already identified and benign.

  • ✗

    Update the signature database on the security tools

    Why it's wrong here

    Updating signatures is a detection-engineering task owned by signature maintenance, not the Tier 1 triage step for a confirmed false positive. The analyst should tune or suppress the offending rule and document the FP so future alerts are not raised. Signature updates are correct when the database itself is stale, not when a rule misfires.

  • ✗

    Initiate the containment process

    Why it's wrong here

    Containment is for confirmed malicious activity; a false positive from an outdated signature requires tuning or suppression, not isolating hosts. Initiating containment on benign traffic disrupts business operations and wastes incident response effort. It tempts because containment is the standard next step once an alert is validated as a true positive.

  • ✓

    Close the alert and document the finding

    Why this is correct

    With the alert confirmed as a false positive from an outdated signature, no genuine incident exists, so the analyst closes it and documents the finding. This preserves the audit trail and supports later tuning of the detection signature.

About these practice questions

Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.