Courseiva

SSCP Risk Identification, Monitoring, and Analysis Practice Question

An analyst is tuning an intrusion detection system that generates far too many alerts. The analyst wants to reduce noise while preserving detection of genuinely suspicious behavior. Which approach BEST supports this goal?

⚠ Common exam trap

The trap here is treating alert volume as a display problem to be hidden with thresholds or severity changes rather than a detection-quality problem to be fixed with baselining.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Baseline normal network and host activity, then write thresholds and correlation rules relative to that baseline.

Alert noise is best reduced by understanding the environment. Baselining normal traffic and behavior gives the analyst a reference point, so thresholds and correlation rules can distinguish expected activity from anomalies. This preserves detection of real threats while eliminating the benign events that flood the console, which is far more effective than suppressing categories or hiding alerts.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Lower the severity rating of all signature-based alerts so analysts can triage them last.

    Why it's wrong here

    Changing severity labels does not reduce the number of alerts or improve their quality; it merely reorders the queue. The same volume of events still arrives, and genuinely suspicious activity may sink below routine noise and be missed. Tuning requires adjusting detection logic or thresholds, not cosmetic severity changes that leave the underlying false-positive rate untouched.

  • ✓

    Baseline normal network and host activity, then write thresholds and correlation rules relative to that baseline.

    Why this is correct

    Baselining establishes what normal looks like for the environment, which lets the analyst set thresholds and correlations that flag meaningful deviations instead of expected traffic. This directly reduces false positives while retaining sensitivity to anomalies such as unusual outbound volume or new service behavior. It is the most effective noise-reduction technique because it adapts detection to the actual environment rather than to generic signatures.

  • ✗

    Disable signature categories that have produced any false positives in the past month.

    Why it's wrong here

    Removing an entire signature category because some alerts were benign discards detection for every genuine threat in that category. Attackers rely on exactly this kind of coverage gap, so broad suppression trades noise for blindness. Effective tuning narrows individual rules or adds exceptions for known-good behavior rather than eliminating whole classes of detection.

  • ✗

    Increase the alert threshold on the console so events are only displayed after they repeat several times.

    Why it's wrong here

    Raising a display threshold hides low-and-slow activity that never repeats within the window, which is precisely the pattern many intrusions follow. It reduces visible noise without addressing the root cause of false positives, and the suppressed events are still generated and stored. Detection quality does not improve because the underlying rules remain untuned.

About these practice questions

One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.