Courseiva
Security Monitoring →mediumMultiple Choice

200-201 Security Monitoring Practice Question

A Cisco Firepower analyst inspects an inline intrusion policy event where the packet was dropped but only a partial payload was captured. The analyst wants to confirm whether the attack was successful on the target host. Which data source should be correlated with the Firepower event?

⚠ Common exam trap

The trap here is assuming that more packet capture or flow data from the same Firepower sensor can prove host compromise, when only endpoint telemetry shows process-level execution.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Endpoint security product telemetry from the target host

When an intrusion event shows a partial payload capture, the network sensor can confirm the attempt but not the outcome on the host. Endpoint telemetry supplies process, file, and registry evidence that ties the network event to actual execution. Correlating the Firepower timestamp and addresses with endpoint records determines whether the attack succeeded, which is the analyst's stated goal.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    NetFlow records exported from the Firepower device

    Why it's wrong here

    NetFlow provides traffic metadata such as source and destination addresses, ports, byte counts, and timestamps, but it does not include the application-layer payload or host-level evidence. In this scenario the analyst needs to determine whether the exploit actually executed on the target, and flow records cannot confirm process creation, file writes, or command execution. NetFlow is useful for traffic profiling, but it is not the data source that verifies endpoint compromise.

  • ✗

    Syslog messages generated by the Firepower management center

    Why it's wrong here

    Syslog from the management center reflects the device's own event generation and policy actions, such as the drop that was already observed. It does not contain process-level evidence from the target host and cannot show whether the exploit succeeded. Relying on the same platform that produced the partial alert creates a circular investigation. The analyst needs independent endpoint data, not additional logging from the intrusion prevention system itself.

  • ✗

    Full packet capture stored on the Firepower device

    Why it's wrong here

    The scenario states that only a partial payload was captured, so the Firepower device does not have the complete packet stream available for re-examination. Even if a full capture existed, it would show the network attempt, not whether the target host executed the payload or created a process. Packet capture answers network-level questions, but the scenario asks for proof of success on the host, which requires endpoint telemetry rather than more packet data.

  • ✓

    Endpoint security product telemetry from the target host

    Why this is correct

    Endpoint detection and response (EDR) or endpoint protection platform telemetry records process execution, file modification, registry changes, and command-line arguments on the target. Correlating the Firepower intrusion event timestamp and source IP with this endpoint data reveals whether the dropped packet was part of a successful exploit chain or whether the host actually spawned a malicious process. This is the authoritative source for confirming host-level compromise after a partial network capture.

About these practice questions

This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.