Courseiva
hardMultiple SelectObjective-mapped

200-201 Practice Question: Which two actions should an analyst take when a…

Which two actions should an analyst take when a security monitoring tool generates a high number of false positives for a specific signature? (Choose two.)

⚠ Common exam trap

Cisco often tests the misconception that disabling a signature or increasing sensitivity is a valid first step for handling false positives, but the correct response is always to tune or whitelist to preserve detection capability.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Create a whitelist for known benign traffic.

Creating a whitelist for known benign traffic allows the analyst to suppress alerts for traffic that is confirmed safe, reducing false positives without losing visibility into actual threats. This approach leverages the security monitoring tool's ability to filter based on source/destination IPs, ports, or application signatures, ensuring that only truly malicious traffic triggers the signature.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Create a whitelist for known benign traffic.

    Why this is correct

    Whitelisting exempts known good traffic from triggering the signature.

  • Tune the signature parameters (e.g., threshold).

    Why this is correct

    Tuning adjusts sensitivity to reduce false positives.

  • Increase the sensitivity of the signature.

    Why it's wrong here

    Increasing sensitivity would generate more false positives.

  • Escalate to management without analysis.

    Why it's wrong here

    Analysts should analyze and mitigate before escalating.

  • Immediately disable the signature.

    Why it's wrong here

    Disabling removes detection and may miss real attacks.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

Courseiva writes every 200-201 question from scratch — 979 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.