350-201 exam dumps

350-201 practice question 121 of 289

Cybersecurity Professional - Performing Cybersecurity Using Cisco Security Technologies. Professional level, Cisco. Free question with the correct answer and a full explanation.

350-201 Question 121

Select 3

A cybersecurity analyst is managing a Cisco Firepower system that is generating a high number of false positive alerts in its intrusion detection system (IDS). The analyst is tasked with tuning the system to reduce these false positives while ensuring legitimate threats are still detected. Which steps should the analyst take to achieve this goal?

  1. A

    Review and refine intrusion rules to disable or modify rules that are consistently flagging benign traffic.

  2. B

    Increase the sensitivity of all intrusion rules to capture as much traffic as possible.

  3. C

    Analyze traffic patterns and whitelist trusted IP addresses or applications generating benign traffic.

  4. D

    Implement stricter geolocation-based filtering to block traffic from specific regions.

  5. E

    Enable automatic updates to keep intrusion rules and filters up-to-date with the latest threat intelligence.

Show answer and explanation

Correct answers: A, C, E

Explanation

To effectively tune the Cisco Firepower IDS, the analyst should focus on refining intrusion rules, analyzing traffic to identify and whitelist benign sources, and ensuring the system is up-to-date with the latest threat intelligence. These steps help reduce false positives while maintaining robust threat detection capabilities.

  • A. Correct.

    Reviewing and refining intrusion rules is a critical step in tuning the system. Disabling or modifying rules that consistently flag benign traffic can significantly reduce false positives.

  • B. Incorrect.

    Increasing the sensitivity of all intrusion rules would likely result in even more false positives, making it harder to identify legitimate threats.

  • C. Correct.

    Analyzing traffic patterns and whitelisting trusted sources can help prevent benign traffic from being flagged, reducing unnecessary alerts.

  • D. Incorrect.

    While geolocation-based filtering can block potentially malicious traffic, it is not directly related to tuning an IDS to reduce false positives.

  • E. Correct.

    Enabling automatic updates ensures the system is using the most current threat intelligence and rule sets, which is essential for accurate threat detection and preventing false positives.

Timed practice exam

Take a 350-201 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam