Courseiva
Security Monitoring →hardMultiple Select

200-201 Security Monitoring Practice Question

An analyst is tuning Snort IDS rules and wants to reduce false positives. Which TWO rule options can be adjusted to decrease sensitivity?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Add a 'suppress' rule to ignore traffic from known benign IPs

Option B is correct because a 'suppress' rule in Snort tells the IDS to ignore alerts generated by a specific rule for a given source or destination IP, which directly eliminates false positives caused by known benign hosts. Option E is correct because 'detection_filter' (or its predecessor 'threshold') requires a specified number of matches within a time interval before an alert fires, raising the bar for triggering and thereby reducing sensitivity to isolated or incidental events. Option A is incorrect because changing the action from 'alert' to 'drop' alters the response mode (inline IPS behavior) rather than decreasing detection sensitivity, and it may even increase impact. Option C is incorrect because switching the protocol from TCP to UDP changes what traffic the rule inspects, not the sensitivity threshold, and would likely miss the intended traffic. Option D is incorrect because increasing priority from low to high only affects alert ranking and does not reduce the number of false positives generated.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Change the rule action from 'alert' to 'drop'

    Why it's wrong here

    Changing the action from alert to drop does not reduce sensitivity; the rule still matches the same traffic, but now blocks it, converting false positives into dropped legitimate sessions. Action selection controls response behaviour, and drop is appropriate when a signature is confirmed accurate and inline prevention is required.

  • ✓

    Add a 'suppress' rule to ignore traffic from known benign IPs

    Why this is correct

    The suppress option tells Snort to ignore traffic matching a specified source or rule, so known benign IPs stop generating alerts. This directly reduces false positives, satisfying the stem's sensitivity-reduction goal, because trusted hosts no longer trigger signatures during routine activity.

  • ✗

    Change protocol from TCP to UDP

    Why it's wrong here

    Changing the protocol to UDP does not reduce sensitivity; it narrows matching to a different transport, causing the rule to miss TCP traffic entirely and produce false negatives instead. Protocol selection defines which traffic the signature inspects, and is chosen to match the threat's actual transport, not to tune alert volume.

  • ✗

    Increase the rule priority from low to high

    Why it's wrong here

    Priority is a classification label used for alert ranking and correlation; raising it from low to high changes how alerts are sorted and escalated, not whether the signature fires. Priority tuning suits environments where analysts need to triage severity, but it cannot suppress the pattern matches causing false positives.

  • ✓

    Use the 'detection_filter' to require a certain number of matches within a time window

    Why this is correct

    detection_filter requires a threshold number of matches within a set time window before Snort alerts, so isolated or sporadic hits are ignored. This raises the effective trigger threshold, satisfying the stem's aim of decreasing sensitivity and cutting false positives from single-packet anomalies.

About these practice questions

This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.