Practise exhibit-style questions that ask you to read a topology, table, command output or diagram before choosing the best answer.
Start Scenario PracticeRefer to the exhibit. An analyst sees this syslog message from a Cisco ASA. What does this log entry indicate?
Explanation: The syslog message shows a deny action for traffic from an external IP (10.10.10.10) to an internal IP (192.168.1.100) on TCP port 443 (HTTPS). The access-group 'OUTSIDE_IN' is applied to the outside interface, and the deny indicates the packet was blocked by an ACL entry. This matches the scenario of an external host attempting to connect to an internal web server and being blocked.
Refer to the exhibit. Which security protocol is being configured?
Explanation: The exhibit shows the configuration of an IPsec VPN IKE phase 1 policy using the `crypto isakmp policy` command. The parameters set—encryption algorithm (e.g., aes), hash algorithm (e.g., sha), Diffie-Hellman group (e.g., 2), and authentication method (e.g., pre-share)—are all specific to IKE phase 1, which establishes a secure authenticated channel for further key exchange. This is not used for SSL VPN, MACsec, or SSH, as those protocols have distinct configuration syntax and purposes.
Refer to the exhibit. What type of activity does this log represent?
Explanation: The log shows repeated SSH connection attempts with 'Failed password' messages from the same source IP (10.10.0.5) to the same destination IP (10.10.0.3) for user 'admin'. This pattern of multiple failed authentication attempts in a short time window is characteristic of a brute force SSH attack, where an attacker systematically tries different passwords to gain unauthorized access.
Refer to the exhibit. Based on the intrusion event, what is the likely intent of the traffic?
Explanation: The intrusion event shows a long string of 'A' characters (0x41) being sent to an HTTP server, which is a classic pattern for a buffer overflow attack. The intent is to overflow a buffer in the web server software, potentially overwriting memory and executing arbitrary code, making D the correct answer.
Refer to the exhibit. A network administrator notices that remote SSH logins to the router succeed, but the router is not sending accounting records. Based on the configuration, what is the most likely cause?
Explanation: The `accounting exec default` command references a TACACS+ server group named 'tacacs_server_group' that is not defined in the configuration. Without a defined server group, the router cannot send accounting records to any TACACS+ server, even though SSH authentication succeeds via the local database.
+10 more scenario questions available
Practice all Refer to the Exhibit Practice QuestionsPractise exhibit-style questions that ask you to read a topology, table, command output or diagram before choosing the best answer. These appear throughout the 200-201 and require you to apply your knowledge, not just recall facts.
Cisco doesn't publish an exact breakdown, but scenario-based questions (especially exhibit and command-output formats) make up a significant portion of the 200-201. Practicing each scenario type ensures you're ready for any format.
Yes. Courseiva provides free 200-201 scenario practice across all official exam domains. The platform includes scenario-based questions, command-output interpretation, topic-based practice, mock exams, and readiness tracking — no account required.
Launch a full Refer to the Exhibit Practice Questions session with instant scoring and detailed explanations.
Start Scenario Practice →