200-201 exam dumps

200-201 practice question 222 of 405

Cisco Cybersecurity Associate. Associate level, Cisco. Free question with the correct answer and a full explanation.

200-201 Question 222

Select 3

A cybersecurity analyst is investigating a suspected malicious activity in a network. They notice an unusually high number of connection attempts from a single IP address targeting multiple hosts in the internal network. Which combination of system and event data would be the most effective to determine if this is a scanning attempt?

  1. A

    NetFlow data to analyze traffic patterns and connection attempts

  2. B

    System logs from the affected hosts to check for login attempts

  3. C

    DNS server logs to review domain resolution requests from the IP address

  4. D

    Firewall logs to identify blocked or allowed connections from the IP address

  5. E

    Intrusion Detection System (IDS) alerts for any suspicious activity

Show answer and explanation

Correct answers: A, D, E

Explanation

To effectively determine if the activity is a scanning attempt, the analyst should use data sources that reveal patterns of connection attempts (NetFlow), confirm blocked or allowed connections (firewall logs), and flag suspicious behaviors (IDS alerts). Together, these provide a comprehensive view of the network activity and help identify reconnaissance or scanning actions.

  • A. Correct.

    NetFlow data provides a summary of network traffic, including the number of connections a source IP attempts, which is crucial to identifying scanning behavior.

  • B. Incorrect.

    System logs from affected hosts are useful for identifying login attempts but are less effective for identifying network-wide scanning activity.

  • C. Incorrect.

    DNS server logs can help identify domain resolution requests but are not directly relevant to identifying scanning activity.

  • D. Correct.

    Firewall logs can show a record of connection attempts, including those that were blocked or allowed, which is essential for detecting unusual scanning patterns.

  • E. Correct.

    Intrusion Detection System (IDS) alerts can provide insights into suspicious activities, such as port scans, making them valuable for confirming scanning behavior.

Timed practice exam

Take a 200-201 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam