SSCP Risk Identification, Monitoring, and Analysis Practice Question
An analyst is tuning an intrusion detection system that generates far too many alerts. The analyst wants to reduce noise while preserving detection of genuinely suspicious behavior. Which approach BEST supports this goal?
⚠ Common exam trap
The trap here is treating alert volume as a display problem to be hidden with thresholds or severity changes rather than a detection-quality problem to be fixed with baselining.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Baseline normal network and host activity, then write thresholds and correlation rules relative to that baseline.
Alert noise is best reduced by understanding the environment. Baselining normal traffic and behavior gives the analyst a reference point, so thresholds and correlation rules can distinguish expected activity from anomalies. This preserves detection of real threats while eliminating the benign events that flood the console, which is far more effective than suppressing categories or hiding alerts.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Lower the severity rating of all signature-based alerts so analysts can triage them last.
Why it's wrong here
Changing severity labels does not reduce the number of alerts or improve their quality; it merely reorders the queue. The same volume of events still arrives, and genuinely suspicious activity may sink below routine noise and be missed. Tuning requires adjusting detection logic or thresholds, not cosmetic severity changes that leave the underlying false-positive rate untouched.
- ✓
Baseline normal network and host activity, then write thresholds and correlation rules relative to that baseline.
Why this is correct
Baselining establishes what normal looks like for the environment, which lets the analyst set thresholds and correlations that flag meaningful deviations instead of expected traffic. This directly reduces false positives while retaining sensitivity to anomalies such as unusual outbound volume or new service behavior. It is the most effective noise-reduction technique because it adapts detection to the actual environment rather than to generic signatures.
- ✗
Disable signature categories that have produced any false positives in the past month.
Why it's wrong here
Removing an entire signature category because some alerts were benign discards detection for every genuine threat in that category. Attackers rely on exactly this kind of coverage gap, so broad suppression trades noise for blindness. Effective tuning narrows individual rules or adds exceptions for known-good behavior rather than eliminating whole classes of detection.
- ✗
Increase the alert threshold on the console so events are only displayed after they repeat several times.
Why it's wrong here
Raising a display threshold hides low-and-slow activity that never repeats within the window, which is precisely the pattern many intrusions follow. It reduces visible noise without addressing the root cause of false positives, and the suppressed events are still generated and stored. Detection quality does not improve because the underlying rules remain untuned.
Go deeper
Related to this question
About these practice questions
One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.