exam questions

Exam 200-201 All Questions

View all questions & answers for the 200-201 exam

Exam 200-201 topic 1 question 237 discussion

Actual exam question from Cisco's 200-201
Question #: 237
Topic #: 1
[All 200-201 Questions]


Refer to the exhibit. A security analyst is investigating unusual activity from an unknown IP address. Which type of evidence is this file?

  • A. indirect evidence
  • B. best evidence
  • C. direct evidence
  • D. corroborative evidence
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
drdecker100
Highly Voted 2 years, 3 months ago
Selected Answer: A
The given information "unusual activity from an unknown IP address" suggests that the evidence in question is indirect evidence, as it does not directly prove who is responsible for the activity, but rather provides a lead for further investigation. Indirect evidence is evidence that requires an inference to connect it to a conclusion, while direct evidence provides clear proof of a fact without requiring an inference.
upvoted 6 times
...
MaliDong
Highly Voted 2 years, 7 months ago
Selected Answer: C
this question is very tricky . here is my thought - it depends on what have to approve. if we need to prove that one guy accessed a system he has no access, then the exhibit is 'indirect evidence'. if we need to prove that someone is doing unusual activity (trying login continues), then this is direct evidence.
upvoted 5 times
...
3000bd6
Most Recent 6 months, 2 weeks ago
Selected Answer: C
While the IP address is unknown, the log entry directly shows suspicious activity (repeated failed login attempts) from a specific IP address. The key here is that direct evidence refers to evidence that, on its own, directly supports a fact or claim without the need for inference. Even though we don't know who the IP address belongs to, the activity itself (failed login attempts) directly points to potential malicious behavior, which is the core reason it's categorized as direct evidence
upvoted 2 times
...
Faio
1 year, 8 months ago
Answer C: In my opinion, this is clear evidence that someone is trying to log into SSH at the address 172.31.27.153
upvoted 1 times
...
SecurityGuy
1 year, 9 months ago
Selected Answer: C
Direct Evidence - It is a general term for any type of evidence that links a defendant directly to a crime. - Samples: Recorded confession by the defendant, Defendant's fingerprints on a weapon used to commit a crime, Surveillance footage of a defendant committing a crime On this case, it is an evidence that directly links the user from 218.26.11.11 https://www.indeed.com/career-advice/career-development/different-types-of-evidence
upvoted 2 times
...
Carvalho
1 year, 9 months ago
Selected Answer: C
Correct ANS=C
upvoted 1 times
...
slippery31
2 years ago
Correct ANS=A
upvoted 1 times
...
evaline12
2 years, 4 months ago
there is no initial evidence so I think its indirect.
upvoted 2 times
...
trigger4848
2 years, 7 months ago
The answer is NOT "C" its "A" indirect evidence
upvoted 1 times
...
trigger4848
2 years, 7 months ago
Answer must be C
upvoted 1 times
...
trigger4848
2 years, 7 months ago
This cannot be direct evidence this is from Cisco: In legal proceedings, evidence is broadly classified as following: • Direct Evidence - The evidence that was indisputably in the possession of the accused, or is eyewitness evidence from someone who directly observed criminal behavior. • Indirect evidence - This evidence establishes a hypothesis in combination with other facts. It is also known as circumstantial evidence. • Best evidence – This evidence could be storage devices used by an accused, or archives of files that can be proven to be unaltered. • Corroborating evidence - This evidence supports an assertion that is developed from best evidence.
upvoted 1 times
...
[Removed]
2 years, 9 months ago
Selected Answer: A
Shouldn't this be Indirect Evidence?
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...