exam questions

Exam 200-201 All Questions

View all questions & answers for the 200-201 exam

Exam 200-201 topic 1 question 118 discussion

Actual exam question from Cisco's 200-201
Question #: 118
Topic #: 1
[All 200-201 Questions]


Refer to the exhibit. An analyst received this alert from the Cisco ASA device, and numerous activity logs were produced. How should this type of evidence be categorized?

  • A. indirect
  • B. circumstantial
  • C. corroborative
  • D. best
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Silexis
10 months, 1 week ago
According to the study guide - Best Evidence is one can be presented in court in original form. As a log, it will satisfy this condition, especially that it is a DENY so there is no successful connection and as the question is not presenting what other logs refer to, we cannot elaborate further
upvoted 1 times
...
SecurityGuy
1 year, 3 months ago
Selected Answer: D
The question doesn't mentioned an existing evidence, corroborative evidence supports another evidence. The other logs is "probably" same as this log. The log counts as a single evidence, we might be overthinking this so I'll choose the simplest answer which is D.
upvoted 1 times
...
Mack279
1 year, 6 months ago
Is the analyst trying to prove that .228 attempted ssh to .77? If yes then the answer is D. But other than that, its C.
upvoted 1 times
...
Lenon
1 year, 7 months ago
A & B auto eliminated since they are same. this leaves only C as correct. It cant be best evidence this one
upvoted 1 times
...
StutiKandpal
1 year, 11 months ago
Selected Answer: C
corroborative
upvoted 2 times
...
trigger4848
2 years ago
Selected Answer: C
not sure how this is best evidence for attribution.. A & B are the same thing indirect = circumstantial so they have to eliminated. That leaves answer C for corroborative.
upvoted 3 times
...
cy_analyst
2 years, 1 month ago
Best is something that you will go to court with. So here you are far away from that.
upvoted 4 times
...
moali012
2 years, 1 month ago
Selected Answer: D
it is direct evidence
upvoted 1 times
...
Eng_ahmedyoussef
2 years, 1 month ago
Selected Answer: C
C is correct answer because numerous activity logs were produced.
upvoted 4 times
...
Ozair
2 years, 2 months ago
why not C ?
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...