Courseiva
Network Intrusion Analysis →mediumMultiple Choice

200-201 Network Intrusion Analysis Practice Question

A SOC analyst sees an alert for 'Possible SQL Injection' on a web server. Reviewing the PCAP, the analyst finds the parameter 'id=1 OR 1=1' in the HTTP request. However, the web server returns a normal page with no signs of compromise. What is the correct classification?

⚠ Common exam trap

200-201 often tests the confusion between false positive and true positive by presenting a detected payload without confirmed compromise — candidates must remember that detection alone does not make it a true positive.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

False positive

A false positive occurs when a security tool raises an alert for activity that is not actually malicious or successful. Here, the SQL injection payload 'id=1 OR 1=1' was detected in the request, but the server returned a normal page with no signs of compromise, meaning the attack did not succeed and the alert was triggered on suspicious input rather than actual exploitation. Therefore, the alert is a false positive.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    True negative

    Why it's wrong here

    A true negative means no malicious activity occurred and no alert fired, yet here an alert did fire on genuine attack syntax. The classification describes correctly identifying benign traffic; it would fit a request containing no injection pattern that generated no alert.

  • ✗

    False negative

    Why it's wrong here

    A false negative means malicious activity occurred but no alert was raised; here the alert fired correctly on the injection string. False negatives describe missed detections, such as an attack bypassing the signature entirely without triggering any alert.

  • ✓

    False positive

    Why this is correct

    The payload 'id=1 OR 1=1' is a classic tautology injection attempt, but the server returned a normal page with no compromise indicators. Because the attack neither succeeded nor altered behaviour, the alert reflects benign traffic rather than a genuine intrusion, so it is classified as a false positive.

  • ✗

    True positive

    Why it's wrong here

    No actual attack was successful.

About these practice questions

One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.