200-201 Security Monitoring Practice Question
A Cisco CyberOps analyst is reviewing a network security monitoring console and must determine which TWO data sources are most useful for detecting lateral movement by an attacker who has already compromised a workstation. (Choose two.)
⚠ Common exam trap
The trap here is choosing external telemetry such as DNS or web proxy logs, which detect command-and-control or initial infection, instead of the internal authentication and flow data that reveal lateral movement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Windows Security event logs collected through Cisco SecureX
Lateral movement is characterized by internal authentication attempts and internal connection fan-out. Windows Security event logs capture logon types and account usage across hosts, while NetFlow from Stealthwatch exposes the internal connection patterns to administrative ports and multiple targets. Together they correlate identity and network behavior to trace an attacker's path. External-focused sources such as DNS, email, and web proxy logs are less relevant once the attacker is moving inside the environment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Windows Security event logs collected through Cisco SecureX
Why this is correct
Windows Security event logs record authentication events such as logon type 3 network logons, explicit credential use, and privileged logon activity. When an attacker moves laterally using stolen credentials or remote execution tools, these logs capture the source workstation, target host, account, and logon type. Correlating these events across endpoints reveals the path of movement. SecureX or a SIEM can aggregate these logs, making them one of the most direct sources for detecting lateral movement in a Windows environment.
- ✗
Email gateway logs from Cisco Email Security Appliance
Why it's wrong here
Email gateway logs record message delivery, spam scoring, and attachment verdicts, which are relevant to initial infection vectors such as phishing. Once an attacker has established a foothold and is moving laterally, email traffic is not the primary channel for that activity. Internal SMB, RDP, and WinRM connections would not appear in email logs. This source helps with identifying patient zero but does not provide the authentication and flow evidence needed to trace movement between internal systems.
- ✗
Web proxy logs from Cisco Web Security Appliance
Why it's wrong here
Web proxy logs show outbound HTTP and HTTPS requests, including URLs and user agents, which help detect command-and-control and data exfiltration. Lateral movement, however, occurs internally and rarely traverses the web proxy. Attackers using SMB, RDP, or WMI between workstations do not generate proxy entries. While proxy logs may reveal an attacker downloading tools before moving, they do not capture the internal authentication and connection patterns that indicate movement across the network.
- ✓
NetFlow records from Cisco Stealthwatch
Why this is correct
NetFlow records show internal-to-internal connections, including source and destination addresses, ports, and byte counts. Lateral movement tools such as SMB, RDP, and WinRM generate distinctive internal flows that deviate from normal peer-to-peer patterns. Stealthwatch baselines these flows and can alert on a workstation initiating connections to many internal hosts or to administrative ports. While flow data lacks payload content, it efficiently exposes the fan-out pattern typical of an attacker enumerating and moving through the network.
- ✗
DNS query logs from Cisco Umbrella
Why it's wrong here
DNS query logs are valuable for detecting command-and-control and exfiltration, but lateral movement within an internal network typically uses IP addresses or hostnames resolved through internal DNS or NetBIOS. External DNS logs may show little about internal SMB or RDP connections between workstations. While an attacker may use DNS for internal reconnaissance, the query logs alone do not capture the authentication and connection patterns that define lateral movement. This source is better suited to detecting external communication than internal propagation.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.