exam questions

Exam 200-201 All Questions

View all questions & answers for the 200-201 exam

Exam 200-201 topic 1 question 128 discussion

Actual exam question from Cisco's 200-201
Question #: 128
Topic #: 1
[All 200-201 Questions]

Which action should be taken if the system is overwhelmed with alerts when false positives and false negatives are compared?

  • A. Modify the settings of the intrusion detection system.
  • B. Design criteria for reviewing alerts.
  • C. Redefine signature rules.
  • D. Adjust the alerts schedule.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
anonymous1966
Highly Voted 3 years, 8 months ago
"A" is correct Traditional intrusion detection system (IDS) and intrusion prevention system (IPS) devices need to be tuned to avoid false positives and false negatives. Next-generation IPSs do not need the same level of tuning compared to traditional IPSs. Also, you can obtain much deeper reports and functionality, including advanced malware protection and retrospective analysis to see what happened after an attack took place. Ref: Cisco CyberOps Associate CBROPS 200-201 Official Cert Guide By Omar Santos
upvoted 15 times
...
74cd09c
Most Recent 8 months, 3 weeks ago
C - false positives and false negatives often result from poorly defined or outdated signature rules in intrusion detection systems (IDS). Redefining or tuning these signature rules helps reduce false positives (legitimate actions being flagged) and false negatives (malicious activity going unnoticed), improving the efficiency of the alert system.
upvoted 1 times
...
fisher004
1 year, 6 months ago
Correct Answer is A
upvoted 2 times
...
Topsecret
1 year, 10 months ago
Selected Answer: B
The correct answer is B. Design criteria for reviewing alerts. When a system is overwhelmed with alerts, indicating a high number of both false positives (incorrectly identifying benign events as threats) and false negatives (failing to detect actual threats), it is important to establish criteria for reviewing alerts. This allows for a more efficient and effective handling of the alerts and helps prioritize the investigation of genuine security incidents. Designing criteria for reviewing alerts involves creating rules or thresholds that filter and prioritize alerts based on their severity, likelihood of being true positives, or other relevant factors. By setting criteria, analysts can focus their efforts on alerts that have a higher probability of being legitimate threats, reducing the time and resources wasted on false positives and irrelevant alerts.
upvoted 1 times
...
Eng_ahmedyoussef
2 years, 7 months ago
Selected Answer: A
A. is correct answer Traditional intrusion detection system (IDS) and intrusion prevention system (IPS) devices need to be tuned to avoid false positives and false negatives.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...