200-201 Security Monitoring Practice Question
A security analyst is creating a network baseline for normal traffic patterns. Which TWO metrics should be included to detect anomalies?
⚠ Common exam trap
Cisco often tests the distinction between network traffic metrics and host/system metrics, so the trap here is confusing server CPU utilization (a host metric) with network baseline metrics, leading candidates to incorrectly select it as a valid network anomaly detection parameter.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Average bandwidth usage per hour
Average bandwidth usage per hour (A) is correct because establishing a normal throughput baseline per time interval lets the analyst spot deviations such as traffic spikes, data exfiltration, or denial-of-service conditions that exceed the expected range. Number of connections per host (C) is correct because connection counts per host reveal abnormal session behavior, such as scanning, beaconing, or worm propagation, that would stand out against the established norm. Geolocation of source IPs (B) is useful context for investigating suspicious traffic but is not itself a traffic-pattern metric for a baseline. MAC addresses of devices (D) are Layer 2 identifiers used for asset inventory or access control, not for measuring normal traffic patterns. CPU utilization of servers (E) is a host performance metric, not a network traffic baseline metric.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Average bandwidth usage per hour
Why this is correct
Average bandwidth usage per hour establishes a quantitative norm for traffic volume, so deviations such as sudden spikes or sustained drops become detectable against the baseline. It directly satisfies the stem's requirement for metrics that reveal anomalies in normal traffic patterns, complementing flow-based measures like protocol distribution or connection counts.
- ✗
Geolocation of source IPs
Why it's wrong here
Geolocation of source IPs is enrichment metadata, not a volumetric or behavioural baseline metric, so it cannot establish normal traffic patterns. It is tempting because geographic origin is genuinely useful for alert triage and blocking, but baselining requires measurable counts such as flow volume and protocol distribution.
- ✓
Number of connections per host
Why this is correct
Tracking connections per host exposes deviations such as beaconing, port scanning or worm propagation, where a single endpoint suddenly opens far more sessions than its established norm. This metric satisfies the stem's requirement for a baseline that flags anomalous traffic volume, complementing flow-level counters rather than relying on payload inspection.
- ✗
MAC addresses of devices
Why it's wrong here
MAC addresses are static hardware identifiers that do not vary with traffic behaviour, so they cannot form a baseline of normal patterns. It is tempting because MAC addresses support asset inventory and rogue-device detection, but anomaly detection baselines require dynamic traffic metrics.
- ✗
CPU utilization of servers
Why it's wrong here
CPU is a system metric, not network.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.