N10-009 Question 210
Single answerAnomaly alerting/notificationA network administrator receives hundreds of security emails overnight from the organization's monitoring platform. Most alerts are triggered by the same branch office router briefly losing connectivity during a scheduled ISP maintenance window. Because the volume of notifications caused the team to miss a separate alert for unusual outbound traffic from a file server, management wants to improve anomaly alerting without losing visibility into real issues. Which action would BEST address this problem?
- A
Configure alert suppression and maintenance windows for the branch router so expected outages do not generate repeated notifications
- B
Disable anomaly alerting for WAN devices and rely on users to report branch connectivity issues
- C
Lower all alert thresholds so the monitoring platform detects every minor change in traffic patterns
- D
Send all monitoring alerts to a single shared mailbox without prioritization so the team can review them later
Show answer and explanation
Correct answer: A
Explanation
The best answer is to configure alert suppression and maintenance windows for expected events. In network operations, anomaly alerting is only effective when notifications are actionable. Excessive alerts from known maintenance or recurring benign events create alert fatigue, which can cause administrators to overlook real incidents. Industry best practices for monitoring platforms and SIEM/NMS tools include baselining normal behavior, tuning thresholds, suppressing duplicate or expected alerts, and using maintenance windows for approved downtime. These practices align with common guidance from network monitoring vendors and operational frameworks focused on event management and incident response. In this scenario, the organization should reduce noise from planned outages so unusual activity, such as unexpected outbound traffic from a file server, stands out and can be investigated promptly.
- A. Correct.
Correct. Defining maintenance windows and suppressing alerts for known, approved events is a standard monitoring best practice. It reduces alert fatigue and helps ensure that meaningful anomalies, such as unexpected outbound traffic from a server, remain visible. In real environments, tuning notifications around scheduled maintenance is one of the most effective ways to improve signal-to-noise ratio.
- B. Incorrect.
Incorrect. Disabling anomaly alerting for WAN devices removes useful monitoring coverage and increases the risk that genuine outages or suspicious patterns will be missed. User reports are reactive and unreliable compared to automated monitoring and alerting.
- C. Incorrect.
Incorrect. Lowering all thresholds would usually increase the number of alerts, not reduce them. That would worsen alert fatigue and make it harder to identify high-priority anomalies. Effective alerting depends on tuning thresholds appropriately, not making them universally more sensitive.
- D. Incorrect.
Incorrect. Sending all alerts to a generic mailbox without prioritization does not solve the root cause of excessive notifications. It can further delay response because important alerts are buried among low-value messages. Best practice is to classify, correlate, suppress, or escalate alerts based on severity and context.