200-201 Security Monitoring Practice Question
A SOC analyst reviewing Cisco Firepower intrusion events notices that a single internal host generated hundreds of alerts for the same signature within a five-minute window, each with a different destination port on the same external IP. The analyst wants to reduce noise before escalating. Which action should the analyst take first?
⚠ Common exam trap
The trap here is assuming that a high volume of alerts automatically means a false positive, when it may instead indicate a real scanning or exploitation attempt.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Correlate the events by source IP and destination IP to determine whether this is a port sweep or a single exploit attempt.
When many alerts share a source and destination but vary in port, the analyst should correlate them to identify the pattern. Grouping by IP pairs reveals whether the activity is a port sweep, a multi-vector exploit, or benign scanning. This context is essential before deciding on containment or tuning.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Export the raw packet captures to a CSV file and archive them for compliance purposes.
Why it's wrong here
Archiving packet captures is a documentation activity, not an investigative or noise-reduction step. It does not help the analyst determine whether the alerts represent a port sweep, a compromised host, or a false positive, and it delays the triage that the situation requires.
- ✓
Correlate the events by source IP and destination IP to determine whether this is a port sweep or a single exploit attempt.
Why this is correct
Correlating the events by source and destination IP reveals the pattern behind the alerts. Hundreds of alerts to the same external IP across different ports strongly suggest scanning or sweep behavior rather than a single exploit, which guides escalation decisions and helps the analyst avoid treating each alert as an isolated incident.
- ✗
Immediately block the internal host's IP address at the perimeter firewall to stop the activity.
Why it's wrong here
Blocking the internal host at the perimeter firewall is a containment action, not a first triage step. Taking that action before confirming whether the host is compromised or simply running a scanner could disrupt business operations, and it would not help the analyst understand the scope or nature of the event pattern.
- ✗
Disable the signature that is generating the alerts because it is clearly producing false positives.
Why it's wrong here
Disabling the signature removes visibility into potentially malicious activity. The high volume of alerts may indicate a real scanning event or a compromised host, so suppressing the rule would hide evidence the analyst needs. Signature tuning should come after analysis, not as an initial reaction to volume.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.