exam questions

Exam 200-201 All Questions

View all questions & answers for the 200-201 exam

Exam 200-201 topic 1 question 232 discussion

Actual exam question from Cisco's 200-201
Question #: 232
Topic #: 1
[All 200-201 Questions]


Refer to the exhibit. During the analysis of a suspicious scanning activity incident, an analyst discovered multiple local TCP connection events. Which technology provided these logs?

  • A. antivirus
  • B. IDS/IPS
  • C. firewall
  • D. proxy
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
genadieff
Highly Voted 2 years ago
ASA - firelwall
upvoted 5 times
...
RoBery
Most Recent 10 months, 3 weeks ago
C The Cisco ASA 5510 Adaptive Security Appliance provides high-performance firewall and VPN services and five integrated 10/100 Fast Ethernet interfaces. It optionally provides high-performance intrusion prevention and worm mitigation services
upvoted 1 times
...
sheyshey
12 months ago
Selected Answer: C
ASA=firewall
upvoted 2 times
...
sheyshey
1 year ago
Selected Answer: B
should this be IDS/IPS? Local TCP connections: The logs mention local connections, meaning traffic originating within the network itself, not inbound or outbound communication. This is a typical scenario for IDS/IPS monitoring, as they are designed to detect suspicious activity within the network perimeter. Scanning activity: The incident involves suspicious scanning, which aligns with the core function of IDS/IPS. They actively monitor network traffic for patterns and signatures indicative of reconnaissance or scanning attempts by potential attackers. Log detail: The image showcases a specific log format with timestamps, connection details, protocols, and potential threats. This level of detail and focus on internal traffic is characteristic of IDS/IPS logs, compared to other options like antivirus or firewall logs.
upvoted 1 times
sheyshey
1 year ago
might be firewall, but please correct me if I'm wrong
upvoted 1 times
Silexis
10 months, 1 week ago
It is an ASA log related to a NAT session
upvoted 1 times
...
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...