Courseiva
Security Monitoring →mediumMultiple Choice

200-201 Security Monitoring Practice Question

A SOC analyst is reviewing Cisco Firepower Intrusion Event logs and notices a high volume of alerts for the signature 'SERVER-WEBAPP Apache Struts2 remote code execution attempt' coming from a single internal host to external web servers. The analyst needs to determine if this is a true positive or a false positive. Which of the following actions would BEST help make that determination?

⚠ Common exam trap

The trap here is assuming that a high volume of alerts automatically indicates a true positive, or that checking the destination reputation is sufficient without examining the actual payload.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Examine the full packet capture associated with the alert to verify if the exploit payload was actually sent and if a response indicating compromise was received.

The most reliable way to determine if an intrusion alert is a true positive is to inspect the raw packets that triggered it. By analyzing the packet capture, the analyst can see the exact payload and the server's response, which provides definitive evidence of whether the exploit attempt was successful or benign. Correlating with other logs or checking reputations can provide supporting context but does not directly confirm the nature of the event.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Correlate the alert with NetFlow records to see if the internal host successfully established a connection and transferred data.

    Why it's wrong here

    NetFlow records can show connection metadata, but they do not contain payload information. Even if a connection was established, it does not confirm whether the exploit succeeded. The absence of a connection might suggest a false positive, but NetFlow alone cannot definitively determine the outcome of the exploit attempt without deeper packet analysis.

  • ✗

    Check the reputation of the external web servers using Cisco Talos Intelligence.

    Why it's wrong here

    Checking the reputation of the external web servers may indicate if the destination is malicious, but the alert is about an attempted exploit from an internal host. If the external servers are benign, it does not prove the internal host is compromised; the internal host could still be launching attacks. This action alone does not provide enough context to classify the alert as true or false positive.

  • ✗

    Review the Snort rule that triggered the alert to understand its detection logic and potential for false positives.

    Why it's wrong here

    Reviewing the rule's logic can help understand why it fired, but it does not provide evidence about the specific event. The rule might be prone to false positives, but without examining the actual traffic, the analyst cannot determine if this instance is a true positive. This action is useful for tuning but not for immediate validation.

  • ✓

    Examine the full packet capture associated with the alert to verify if the exploit payload was actually sent and if a response indicating compromise was received.

    Why this is correct

    Examining the full packet capture allows the analyst to see the actual payload and server response. If the payload matches known exploit patterns and the server responds with a shell or unusual behavior, it is a true positive. If the payload is benign or the server rejects it, it may be a false positive. This is the most direct method to validate the alert.

About these practice questions

One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.