200-201 Security Monitoring Practice Question
An analyst is tuning Snort IDS rules and wants to reduce false positives. Which TWO rule options can be adjusted to decrease sensitivity?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Add a 'suppress' rule to ignore traffic from known benign IPs
Option B is correct because a 'suppress' rule in Snort tells the IDS to ignore alerts generated by a specific rule for a given source or destination IP, which directly eliminates false positives caused by known benign hosts. Option E is correct because 'detection_filter' (or its predecessor 'threshold') requires a specified number of matches within a time interval before an alert fires, raising the bar for triggering and thereby reducing sensitivity to isolated or incidental events. Option A is incorrect because changing the action from 'alert' to 'drop' alters the response mode (inline IPS behavior) rather than decreasing detection sensitivity, and it may even increase impact. Option C is incorrect because switching the protocol from TCP to UDP changes what traffic the rule inspects, not the sensitivity threshold, and would likely miss the intended traffic. Option D is incorrect because increasing priority from low to high only affects alert ranking and does not reduce the number of false positives generated.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Change the rule action from 'alert' to 'drop'
Why it's wrong here
Changing the action from alert to drop does not reduce sensitivity; the rule still matches the same traffic, but now blocks it, converting false positives into dropped legitimate sessions. Action selection controls response behaviour, and drop is appropriate when a signature is confirmed accurate and inline prevention is required.
- ✓
Add a 'suppress' rule to ignore traffic from known benign IPs
Why this is correct
The suppress option tells Snort to ignore traffic matching a specified source or rule, so known benign IPs stop generating alerts. This directly reduces false positives, satisfying the stem's sensitivity-reduction goal, because trusted hosts no longer trigger signatures during routine activity.
- ✗
Change protocol from TCP to UDP
Why it's wrong here
Changing the protocol to UDP does not reduce sensitivity; it narrows matching to a different transport, causing the rule to miss TCP traffic entirely and produce false negatives instead. Protocol selection defines which traffic the signature inspects, and is chosen to match the threat's actual transport, not to tune alert volume.
- ✗
Increase the rule priority from low to high
Why it's wrong here
Priority is a classification label used for alert ranking and correlation; raising it from low to high changes how alerts are sorted and escalated, not whether the signature fires. Priority tuning suits environments where analysts need to triage severity, but it cannot suppress the pattern matches causing false positives.
- ✓
Use the 'detection_filter' to require a certain number of matches within a time window
Why this is correct
detection_filter requires a threshold number of matches within a set time window before Snort alerts, so isolated or sporadic hits are ignored. This raises the effective trigger threshold, satisfying the stem's aim of decreasing sensitivity and cutting false positives from single-packet anomalies.
Go deeper
Related to this question
About these practice questions
This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.