Courseiva
Security Monitoring →mediumMultiple Choice

200-201 Security Monitoring Practice Question

A SOC analyst is tuning IDS signatures and notices that a particular signature triggers frequently on legitimate traffic from a specific internal application. The signature has a high false positive rate. What is the best action to take?

⚠ Common exam trap

Candidates often confuse 'reduce false positives' with 'disable the noisy rule' — candidates often pick the most drastic action (disable) instead of the surgical one (suppress specific source), missing that the exam tests least-disruptive tuning.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a suppression rule to ignore the specific source IP or application.

A suppression rule is the correct tuning action because it preserves the signature's detection capability for all other traffic while filtering out the known-good source IP or application that generates the false positives. This is the standard IDS/IPS tuning practice: narrow the exception rather than removing the detection entirely. It maintains visibility into genuine attacks using the same signature from other sources.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Disable the signature entirely.

    Why it's wrong here

    Disabling removes detection coverage entirely, so genuine attacks matching that signature go unnoticed. Disabling suits signatures proven obsolete or wholly redundant, whereas a high false-positive rate on legitimate application traffic calls for tuning thresholds or excluding that traffic, preserving detection.

  • ✗

    Increase the severity of the signature to get more attention.

    Why it's wrong here

    Raising severity amplifies noise without reducing the false positives, so legitimate traffic keeps flooding the SOC and genuine alerts get buried. It is tempting because severity tuning is a real triage lever, and it would be correct when a true-positive signature is under-prioritised, not when the signature itself is inaccurate.

  • ✓

    Create a suppression rule to ignore the specific source IP or application.

    Why this is correct

    Suppression rules let the IDS ignore matching traffic from the specific source IP or application while retaining the signature for all other sources, eliminating the recurring false positives without losing genuine detection coverage. This directly addresses the high false-positive rate constraint.

  • ✗

    Change the signature action to 'alert' instead of 'drop'.

    Why it's wrong here

    Changing the action to alert still generates a high volume of false positives, so analysts keep triaging legitimate application traffic; it merely stops blocking it. Alert-only suits signatures you want to monitor without disruption, not one whose detection logic itself is faulty and needs threshold or exception tuning.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.