nerdexam
Cisco

350-201(NEW-127Q) · Question #65

A security operations team is experiencing frequent false positives from detection rules designed to flag suspicious outbound network traffic in their SIEM system. The rules are based on traffic…

The correct answer is C. Baseline normal traffic patterns, refine rule thresholds, and automate IP allow list synchronization. Option C is correct because it addresses false positives at the root cause: the team lacks an accurate picture of what "normal" looks like. Baselining normal traffic establishes realistic thresholds, rule refinement tunes detection logic to reduce noise without losing coverage…

Threat Detection and Analysis

Question

A security operations team is experiencing frequent false positives from detection rules designed to flag suspicious outbound network traffic in their SIEM system. The rules are based on traffic volume, specific IP address ranges, and known malicious domains. Legitimate business applications with high traffic and dynamic IPs are often triggering alerts. Which set of troubleshooting approaches should the team take to improve the accuracy of the detection rules?

Options

  • AIncrease traffic thresholds, remove IP-based rules, and rely on domain matching only.
  • BTurn off alerts temporarily and only monitor manually for high-risk domains.
  • CBaseline normal traffic patterns, refine rule thresholds, and automate IP allow list synchronization.
  • DDisable current rules and create entirely new ones based on traffic volume.

How the community answered

(17 responses)
  • A
    29% (5)
  • B
    6% (1)
  • C
    53% (9)
  • D
    12% (2)

Explanation

Option C is correct because it addresses false positives at the root cause: the team lacks an accurate picture of what "normal" looks like. Baselining normal traffic establishes realistic thresholds, rule refinement tunes detection logic to reduce noise without losing coverage, and automated IP allow list synchronization solves the dynamic IP problem without requiring constant manual updates.

Why the distractors fail:

  • A is wrong because removing IP-based rules entirely eliminates a valuable detection layer - the problem is misconfigured thresholds, not the use of IPs.
  • B is wrong because disabling alerts and relying on manual monitoring defeats the purpose of a SIEM and creates dangerous coverage gaps.
  • D is wrong because the issue is rule tuning, not rule replacement - discarding existing rules throws away accumulated detection logic and restarts from zero without fixing the underlying misconfiguration.

Memory tip: Think of C as the "tune, don't trash" approach - in security operations, the answer to noisy rules is always calibration (baseline → refine → automate), never wholesale removal or manual-only fallback. If an answer involves abandoning automation or deleting coverage entirely, it's almost certainly wrong on a SOC exam.

Topics

#SIEM#Detection Rules#False Positives#Baselining

Community Discussion

No community discussion yet for this question.

Full 350-201(NEW-127Q) Practice