200-201 Security Monitoring Practice Question
A network engineer is deploying a Cisco Next-Generation IPS (NGIPS) in inline mode. The security team wants to ensure that the device can block malicious traffic while also providing contextual information about the attack. Which of the following Cisco NGIPS features provides detailed information about the attack and the target, including vulnerability mapping?
⚠ Common exam trap
Candidates often confuse policy configuration features with analysis and contextual features; only FireSIGHT provides vulnerability mapping and impact assessment.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
FireSIGHT (now Cisco Firepower) correlation and impact flags
The correct answer is the feature that correlates intrusion events with host vulnerability data. Cisco Firepower's FireSIGHT technology provides impact flags that indicate whether an attack is relevant to the target's vulnerabilities, giving analysts the context needed to prioritize response. This goes beyond simple signature matching.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
FireSIGHT (now Cisco Firepower) correlation and impact flags
Why this is correct
FireSIGHT (now integrated into Cisco Firepower) correlates intrusion events with host vulnerability data to provide impact flags and contextual information. This helps analysts understand the severity and potential impact of an attack by mapping it to known vulnerabilities on the target host.
- ✗
Access Control Policy with URL filtering
Why it's wrong here
Access Control Policy with URL filtering controls which traffic is allowed or blocked based on URL categories, but it does not provide detailed attack context or vulnerability mapping. It is a policy enforcement mechanism, not an analysis feature.
- ✗
Network Analysis Policy (NAP)
Why it's wrong here
Network Analysis Policy defines how traffic is decoded and normalized for inspection, but it does not provide vulnerability mapping or attack context. It is a configuration layer that prepares packets for the intrusion policy, not a reporting or contextual feature.
- ✗
Security Intelligence (SI)
Why it's wrong here
Security Intelligence feeds provide reputation-based blocking of known malicious IPs, domains, and URLs, but they do not provide detailed vulnerability mapping or contextual attack information. They are useful for rapid blocking but lack the deep inspection and context of other features.
Go deeper
Related to this question
About these practice questions
This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.