exam questions

Exam 200-201 All Questions

View all questions & answers for the 200-201 exam

Exam 200-201 topic 1 question 53 discussion

Actual exam question from Cisco's 200-201
Question #: 53
Topic #: 1
[All 200-201 Questions]


Refer to the exhibit. Which type of log is displayed?

  • A. IDS
  • B. proxy
  • C. NetFlow
  • D. sys
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
andrewdh
Highly Voted 3 years ago
No - This is a IDS/IPS log. Look at the Signature ID
upvoted 40 times
samismayilov
2 years, 9 months ago
agreed
upvoted 5 times
...
...
bren_
Highly Voted 2 years, 11 months ago
Sig. ID is there, therefore the answer could be A: IDS
upvoted 13 times
...
slippery31
Most Recent 7 months ago
Correct ANS= A
upvoted 1 times
...
alhamry
7 months, 3 weeks ago
The answer is D (IDS) The log entry contains information about a signature ID, source and destination IP addresses, source and destination ports, and a severity rating. These are characteristics typically found in IDS logs (Intrusion Detection System). IDS logs provide information about security events detected by an IDS system, which monitors network traffic for signs of unauthorized activity or security policy violations. On the other hand, proxy logs record client connections to a proxy server, NetFlow logs capture network traffic data, and syslogs are a type of system log that captures messages from various components of a computer system.
upvoted 2 times
alhamry
7 months, 3 weeks ago
sorry it's A (IDS)
upvoted 2 times
...
...
drdecker100
10 months, 1 week ago
Selected Answer: A
"Sig ID" typically refers to a Signature ID, which is a unique identifier assigned to a particular security threat or event by an intrusion detection or prevention system (IDS/IPS). A log message that includes a Sig ID would suggest that the message is related to an alert triggered by the IDS/IPS in response to a security event.
upvoted 2 times
...
cy_analyst
1 year, 2 months ago
Selected Answer: A
IDS and firewalls uses signatures.
upvoted 1 times
...
Entivo
1 year, 4 months ago
Selected Answer: A
Looks more like an IDS/IPS log to me. Syslog doesn't have a Signature ID field so it can't be that.
upvoted 1 times
...
addpro7
1 year, 8 months ago
Selected Answer: A
You also see the 5-tuple in IPS events, NetFlow records, and other event data. In fact, on the exam you may need to differentiate between a firewall log versus a traditional IPS or IDS event. One of the things to remember is that traditional IDS and IPS use signatures, so an easy way to differentiate is by looking for a signature ID (SigID). If you see a signature ID, then most definitely the event is a traditional IPS or IDS event. Cisco CyberOps Associate_P861 CBROPS 200-201 Official Cert Guide Omar Santos
upvoted 4 times
...
Dunky
1 year, 9 months ago
OK - so what has the severity got to do with and IDS. Severity 6 is a syslog feature and means informational and represents a normal event. Why would a normal even have a sig id?
upvoted 1 times
...
aiglart
1 year, 9 months ago
Selected Answer: A
A should be the answer, signature ID.
upvoted 1 times
...
CiscoTerminator
2 years ago
Selected Answer: A
SIG ID is present so IDS/IPS
upvoted 3 times
...
halamah
2 years, 1 month ago
a is corrects ids log
upvoted 2 times
...
alocin
2 years, 2 months ago
you are right there is the signature ID column, but the first column is Severity
upvoted 2 times
...
Fafabeans
3 years ago
Agreed.
upvoted 8 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...