nerdexam
Cisco

200-201 · Question #144

Which action should be taken if the system is overwhelmed with alerts when false positives and false negatives are compared?

The correct answer is A. Modify the settings of the intrusion detection system. Traditional intrusion detection system (IDS) and intrusion prevention system (IPS) devices need to be tuned to avoid false positives and false negatives. Next-generation IPSs do not need the same level of tuning compared to traditional IPSs. Also, you can obtain much deeper…

Submitted by renata2k· Mar 6, 2026Security Monitoring

Question

Which action should be taken if the system is overwhelmed with alerts when false positives and false negatives are compared?

Options

  • AModify the settings of the intrusion detection system.
  • BDesign criteria for reviewing alerts.
  • CRedefine signature rules.
  • DAdjust the alerts schedule.

How the community answered

(34 responses)
  • A
    79% (27)
  • B
    12% (4)
  • C
    6% (2)
  • D
    3% (1)

Explanation

Traditional intrusion detection system (IDS) and intrusion prevention system (IPS) devices need to be tuned to avoid false positives and false negatives. Next-generation IPSs do not need the same level of tuning compared to traditional IPSs. Also, you can obtain much deeper reports and functionality, including advanced malware protection and retrospective analysis to see what happened after an attack took place.

Topics

#alert tuning#IDS/IPS configuration#false positives#security operations

Community Discussion

No community discussion yet for this question.

Full 200-201 Practice