Courseiva
hardMultiple Choice

IPS Signature Tuning — Reducing False Positives

An IPS sensor is configured inline and drops traffic that triggers the signature 'OVERFLOW-ICMP-ECHO', which triggers on ICMP packets with size > 1024 bytes. A network administrator reports that legitimate network monitoring tools using large ICMP packets are being blocked. What is the best course of action?

⚠ Common exam trap

Cisco often tests the misconception that you should adjust the signature threshold (option A) to fix false positives, but the correct approach is to use a whitelist or exception rule to allow known legitimate traffic without weakening the overall security posture.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a whitelist for the monitoring tool's source IP

Creating a whitelist for the monitoring tool's source IP allows the IPS to continue dropping malicious oversized ICMP packets while permitting legitimate traffic from known, trusted sources. This maintains security for the rest of the network without disabling the signature or changing its mode, which would reduce protection.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Increase the threshold to 2048

    Why it's wrong here

    Raising the threshold to 2048 still drops legitimate monitoring traffic exceeding that size, and the signature's purpose is detecting oversized ICMP floods, not tuning. Threshold tuning suits environments where a known benign packet size sits below a genuine attack volume, letting the signature fire only above it.

  • ✓

    Create a whitelist for the monitoring tool's source IP

    Why this is correct

    A whitelist exempts the monitoring tool's trusted source IP from the ICMP size signature, satisfying the constraint of preserving legitimate large-packet monitoring while still blocking genuine overflow attempts. This is more precise than disabling the signature, which would remove detection entirely.

  • ✗

    Disable the signature entirely

    Why it's wrong here

    Disabling the signature removes detection of genuine oversized-ICMP overflow attempts, leaving that attack class entirely unprotected. It is tempting because it immediately restores the monitoring traffic, which would be acceptable only if the signature produced constant false positives with no legitimate matching traffic and no compensating control existed.

  • ✗

    Change the sensor mode to IDS for that signature

    Why it's wrong here

    Switching to IDS mode stops the sensor dropping the packets, but the signature still alerts on every legitimate large ICMP packet, flooding analysts with false positives. It is tempting because it preserves visibility, which would be correct for auditing suspicious traffic without disrupting production flows.

About these practice questions

Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.