An IDS/IPS alert shows a signature named 'ET POLICY Outgoing HTTP Request with Suspicious User-Agent' with severity high. What is the most likely next step for an analyst?
The signature flags an unusual User-Agent in outbound HTTP, which may indicate malware beaconing or command-and-control traffic. Correlating the source IP with the User-Agent string confirms whether the host is compromised, satisfying the need to validate the alert before escalation.
Why this answer
The 'ET POLICY Outgoing HTTP Request with Suspicious User-Agent' signature indicates a policy violation, not necessarily a confirmed attack. An analyst must first investigate the source IP and user-agent to determine if the traffic is malicious (e.g., command-and-control communication, data exfiltration) or benign (e.g., a legitimate application using a non-standard user-agent). Immediate blocking (Option A) could disrupt legitimate services, while ignoring the alert (Option D) risks missing a real threat.
Exam trap
Cisco often tests the distinction between 'policy' and 'exploit' signatures, where candidates mistakenly treat a policy violation as an immediate threat and jump to blocking, rather than following the proper incident response process of investigation first.
How to eliminate wrong answers
Option A is wrong because immediately blocking the source IP on the firewall is an overly aggressive response without confirming malicious activity; it could cause a denial of service for legitimate users and violates the principle of 'verify before blocking'. Option B is wrong because resetting the IDS/IPS signature database does not address the alert; it would remove all signatures, including legitimate ones, and is not a standard troubleshooting step for a single alert. Option D is wrong because ignoring the alert is negligent; even though it is a policy-based signature, it may indicate reconnaissance, scanning, or malware activity that requires investigation.