CCNA Network Services and Security Practice Question
Which two statements accurately describe why logs and accounting records both matter in secure operations?
⚠ Common exam trap
Don't confuse logs and accounting records with access control measures; they are about visibility and traceability, not prevention.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
They improve visibility into events and activity after access occurs.
Logs and accounting records both matter because security is not only about preventing access, but also about understanding what happened. In practical terms, logs can provide event visibility and system context, while accounting records can add traceability for user activity and access sessions. Together they improve incident review and operational accountability. This is a visibility-and-traceability question, not a pure prevention question.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
They improve visibility into events and activity after access occurs.
Why this is correct
This is correct because both support post-event understanding and investigation.
- ✓
They help with accountability and incident review.
Why this is correct
This is correct because records of events and actions make audits and investigations more meaningful.
- ✗
They replace the need for authentication entirely.
Why it's wrong here
This is wrong because visibility does not replace identity verification.
When this WOULD be correct
In a question focused on theoretical frameworks for security models, such as 'What are the implications of eliminating authentication in a secure system?', option C could be correct if discussing a hypothetical scenario where logs are used as the sole method of access control, which is not practical but could be a point of discussion.
- ✗
They are useful only on wireless guest networks.
Why it's wrong here
This is wrong because logging and accounting matter broadly across environments.
When this WOULD be correct
In a question focused specifically on the security measures applicable to wireless guest networks, where the context emphasizes the unique challenges and requirements of managing guest access, this option could be correct if it stated that logs are particularly useful in that scenario.
- ✗
They automatically create access policies for administrators.
Why it's wrong here
This is wrong because records do not automatically define authorization policy.
When this WOULD be correct
If the exam question were to ask about automated systems that utilize logs to dynamically adjust access controls based on user behavior, then this option could be correct. For example, a question about a security system that analyzes logs to enforce real-time access policies would validate this statement.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The 200-301 exam frequently reuses these exact scenarios with slightly different constraints.
✓They improve visibility into events and activity after access occurs.Correct answer▾
Why this is correct
This is correct because both support post-event understanding and investigation.
✗They replace the need for authentication entirely.Wrong answer — click to see why▾
Why this is wrong here
Logs and accounting records do not replace authentication; they complement it by recording who accessed what and when. Authentication is still required to verify identity before access is granted, and logs only capture activity after authentication occurs.
★ When this WOULD be the correct answer
In a question focused on theoretical frameworks for security models, such as 'What are the implications of eliminating authentication in a secure system?', option C could be correct if discussing a hypothetical scenario where logs are used as the sole method of access control, which is not practical but could be a point of discussion.
Why candidates choose this
Students might think that because logs provide visibility into user actions, they could substitute for authentication. However, authentication is a prerequisite for logging meaningful data, and without it, logs cannot identify who performed an action.
✗They are useful only on wireless guest networks.Wrong answer — click to see why▾
Why this is wrong here
Logging and accounting are essential across all network segments, including wired, wireless, VPN, and data center environments. Limiting them to wireless guest networks would leave other critical areas unmonitored, creating security gaps.
★ When this WOULD be the correct answer
In a question focused specifically on the security measures applicable to wireless guest networks, where the context emphasizes the unique challenges and requirements of managing guest access, this option could be correct if it stated that logs are particularly useful in that scenario.
Why candidates choose this
A student might associate accounting with guest network portals that require login, but accounting is a broader concept used in AAA (Authentication, Authorization, and Accounting) for all network access, not just guest networks.
✗They automatically create access policies for administrators.Wrong answer — click to see why▾
Why this is wrong here
Logs and accounting records are passive records of events; they do not automatically create or modify access policies. Policy creation requires administrative action based on analysis of logs, not the logs themselves.
★ When this WOULD be the correct answer
If the exam question were to ask about automated systems that utilize logs to dynamically adjust access controls based on user behavior, then this option could be correct. For example, a question about a security system that analyzes logs to enforce real-time access policies would validate this statement.
Why candidates choose this
Some might confuse accounting with authorization, thinking that because accounting tracks usage, it can automatically adjust policies. However, accounting is about recording, not enforcing or defining access rules.
Analysis generated from the official 200-301blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
About these practice questions
This 200-301 question is part of Courseiva's 1,389-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-301 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-301 exam.