Courseiva
Security Monitoring →easyMultiple Select

200-201 Security Monitoring Practice Question

A network analyst is creating a baseline for normal network traffic. Which TWO metrics should be included to establish a baseline?

⚠ Common exam trap

Candidates often confuse anomaly indicators (excessive connection attempts, unusual payload sizes) with baseline metrics — the exam expects you to recognize that baselines describe normal behavior, while anomalies are deviations from it.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Average bandwidth usage over time

Option A (Average bandwidth usage over time) is correct because a traffic baseline must capture the normal volume of data traversing the network, and averaging utilization over representative periods establishes the expected throughput level against which anomalies can be measured. Option D (Typical protocol distribution, e.g., HTTP vs DNS) is correct because a baseline should document which protocols normally appear and in what proportions, so deviations such as unexpected SMB, IRC, or DNS tunneling traffic become detectable. Options B (Excessive connection attempts from a single IP) and E (Unusual payload sizes) describe anomalies or attack indicators rather than normal-behavior metrics, so they are things a baseline helps you identify, not components used to define the baseline itself. Option C (Peak traffic times) is a useful contextual detail but is not one of the two core metrics for establishing a normal-traffic baseline in this scenario.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Average bandwidth usage over time

    Why this is correct

    Average bandwidth usage over time establishes the quantitative normal for link utilisation, so deviations such as spikes or sustained increases become detectable. This metric underpins anomaly-based monitoring, satisfying the baseline requirement for measurable traffic volume.

  • ✗

    Excessive connection attempts from a single IP

    Why it's wrong here

    Excessive connection attempts from a single IP is a signature of scanning or brute-force activity, an anomaly rather than a normal-traffic metric. It is tempting because connection counts feed intrusion detection, which would be correct when alerting on deviations from an established baseline, not when building it.

  • ✗

    Peak traffic times

    Why it's wrong here

    Peak traffic times record when volume is highest, not the recurring volume, protocol and flow characteristics that constitute a traffic baseline. It is tempting because timing data supports capacity planning and scheduling, which would be correct for that purpose rather than for establishing normal-traffic metrics.

  • ✓

    Typical protocol distribution (e.g., HTTP vs DNS)

    Why this is correct

    Typical protocol distribution records which protocols normally traverse the network and in what proportion. Shifts, such as unexpected SMB or DNS volume, reveal anomalies. This composition metric complements volume metrics, satisfying the baseline requirement for protocol-level normalcy.

  • ✗

    Unusual payload sizes

    Why it's wrong here

    Unusual payload sizes describe anomalies deviating from established norms, so they cannot define the baseline itself. It is tempting because payload size analysis supports anomaly detection, which would be correct when comparing live traffic against an already-documented baseline rather than constructing one.

About these practice questions

One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.