Courseiva

200-201 Network Intrusion Analysis Practice Question

An analyst receives an alert for 'ET WEB_SERVER Possible SQL Injection Attempt' triggered by a URL parameter containing ' OR 1=1--'. After investigating, the analyst confirms that the web application is not vulnerable to SQL injection and the request was a benign test. How should this alert be classified?

⚠ Common exam trap

200-201 often tests whether candidates can correctly classify alerts based on the definitions of true/false positives/negatives, so the trap is confusing a false positive with a true negative or true positive when the activity is benign but an alert was raised.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

False positive

A false positive occurs when an alert is triggered but the activity is actually benign. Here, the SQL injection attempt was a benign test and the application is not vulnerable, so the alert is a false positive. This classification is correct because the detection system incorrectly flagged legitimate activity as malicious.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    False positive

    Why this is correct

    The signature fired on a string resembling SQL injection, but investigation confirmed the application is not vulnerable and the traffic was a benign test. The alert therefore correctly identified suspicious syntax yet wrongly indicated an actual attack, which is a false positive.

  • ✗

    True negative

    Why it's wrong here

    A true negative describes no alert at all, yet the IDS did fire, so the event was detected. It is tempting because the request was genuinely benign, but true negative applies only when the system correctly stays silent — here the signature matched, making it a false positive instead.

  • ✗

    False negative

    Why it's wrong here

    A false negative is an attack the detection system misses entirely; here the alert fired, so the classification is wrong on its face. It tempts because the request was benign, but false negative describes undetected malicious traffic, whereas this event is a false positive requiring tuning.

  • ✗

    True positive

    Why it's wrong here

    The signature fired but the application is not vulnerable and the request was benign, so no actual attack occurred. True positive is tempting because the alert did trigger on real traffic, but it requires the detected activity to be genuinely malicious, which the investigation ruled out.

About these practice questions

This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.