200-201 Network Intrusion Analysis Practice Question
A SOC analyst sees an alert for 'Possible SQL Injection' on a web server. Reviewing the PCAP, the analyst finds the parameter 'id=1 OR 1=1' in the HTTP request. However, the web server returns a normal page with no signs of compromise. What is the correct classification?
⚠ Common exam trap
200-201 often tests the confusion between false positive and true positive by presenting a detected payload without confirmed compromise — candidates must remember that detection alone does not make it a true positive.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
False positive
A false positive occurs when a security tool raises an alert for activity that is not actually malicious or successful. Here, the SQL injection payload 'id=1 OR 1=1' was detected in the request, but the server returned a normal page with no signs of compromise, meaning the attack did not succeed and the alert was triggered on suspicious input rather than actual exploitation. Therefore, the alert is a false positive.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
True negative
Why it's wrong here
A true negative means no malicious activity occurred and no alert fired, yet here an alert did fire on genuine attack syntax. The classification describes correctly identifying benign traffic; it would fit a request containing no injection pattern that generated no alert.
- ✗
False negative
Why it's wrong here
A false negative means malicious activity occurred but no alert was raised; here the alert fired correctly on the injection string. False negatives describe missed detections, such as an attack bypassing the signature entirely without triggering any alert.
- ✓
False positive
Why this is correct
The payload 'id=1 OR 1=1' is a classic tautology injection attempt, but the server returned a normal page with no compromise indicators. Because the attack neither succeeded nor altered behaviour, the alert reflects benign traffic rather than a genuine intrusion, so it is classified as a false positive.
- ✗
True positive
Why it's wrong here
No actual attack was successful.
Go deeper
Related to this question
About these practice questions
One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.