Courseiva
hardMultiple ChoiceObjective-mapped

200-201 Practice Question: A SOC analyst is tuning a correlation rule that…

A SOC analyst is tuning a correlation rule that detects DNS tunneling. The rule currently generates 500 alerts per day, but only 5% are true positives. Which tuning approach would best reduce false positives while maintaining detection efficacy?

⚠ Common exam trap

Cisco often tests the misconception that lowering a threshold (like entropy) always reduces false positives, when in fact it can have the opposite effect by making the rule more sensitive to benign traffic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Add a condition that the number of unique domains queried per source IP exceeds 10 per minute.

DNS tunneling typically involves a single infected host querying many unique domains (often algorithmically generated) at a high rate to exfiltrate data. By requiring more than 10 unique domains per minute per source IP, the rule filters out low-volume, legitimate DNS traffic that may have slightly random-looking domains, while still catching the high-frequency queries characteristic of active tunneling. This reduces the false positive rate from 95% to a more manageable level without requiring a lower entropy threshold that would miss subtle tunneling.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Lower the entropy threshold for domain names from 3.5 to 2.0.

    Why it's wrong here

    Lower entropy threshold includes more benign domains, increasing false positives.

  • Disable the rule and rely on manual review of DNS logs.

    Why it's wrong here

    Manual review is not scalable and may miss attacks.

  • Increase the observation time window from 1 hour to 24 hours.

    Why it's wrong here

    A longer window may include more benign traffic, increasing false positives.

  • Add a condition that the number of unique domains queried per source IP exceeds 10 per minute.

    Why this is correct

    This threshold helps differentiate tunneling from normal DNS behavior.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

This 200-201 question is part of Courseiva's 979-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.