200-201 Security Monitoring Practice Question
A Cisco Firepower analyst inspects an inline intrusion policy event where the packet was dropped but only a partial payload was captured. The analyst wants to confirm whether the attack was successful on the target host. Which data source should be correlated with the Firepower event?
⚠ Common exam trap
The trap here is assuming that more packet capture or flow data from the same Firepower sensor can prove host compromise, when only endpoint telemetry shows process-level execution.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Endpoint security product telemetry from the target host
When an intrusion event shows a partial payload capture, the network sensor can confirm the attempt but not the outcome on the host. Endpoint telemetry supplies process, file, and registry evidence that ties the network event to actual execution. Correlating the Firepower timestamp and addresses with endpoint records determines whether the attack succeeded, which is the analyst's stated goal.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
NetFlow records exported from the Firepower device
Why it's wrong here
NetFlow provides traffic metadata such as source and destination addresses, ports, byte counts, and timestamps, but it does not include the application-layer payload or host-level evidence. In this scenario the analyst needs to determine whether the exploit actually executed on the target, and flow records cannot confirm process creation, file writes, or command execution. NetFlow is useful for traffic profiling, but it is not the data source that verifies endpoint compromise.
- ✗
Syslog messages generated by the Firepower management center
Why it's wrong here
Syslog from the management center reflects the device's own event generation and policy actions, such as the drop that was already observed. It does not contain process-level evidence from the target host and cannot show whether the exploit succeeded. Relying on the same platform that produced the partial alert creates a circular investigation. The analyst needs independent endpoint data, not additional logging from the intrusion prevention system itself.
- ✗
Full packet capture stored on the Firepower device
Why it's wrong here
The scenario states that only a partial payload was captured, so the Firepower device does not have the complete packet stream available for re-examination. Even if a full capture existed, it would show the network attempt, not whether the target host executed the payload or created a process. Packet capture answers network-level questions, but the scenario asks for proof of success on the host, which requires endpoint telemetry rather than more packet data.
- ✓
Endpoint security product telemetry from the target host
Why this is correct
Endpoint detection and response (EDR) or endpoint protection platform telemetry records process execution, file modification, registry changes, and command-line arguments on the target. Correlating the Firepower intrusion event timestamp and source IP with this endpoint data reveals whether the dropped packet was part of a successful exploit chain or whether the host actually spawned a malicious process. This is the authoritative source for confirming host-level compromise after a partial network capture.
Go deeper
Related to this question
About these practice questions
This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.