Courseiva
Security Monitoring →easyMultiple Select

200-201 Security Monitoring Practice Question

A security analyst is creating a network baseline for normal traffic patterns. Which TWO metrics should be included to detect anomalies?

⚠ Common exam trap

Cisco often tests the distinction between network traffic metrics and host/system metrics, so the trap here is confusing server CPU utilization (a host metric) with network baseline metrics, leading candidates to incorrectly select it as a valid network anomaly detection parameter.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Average bandwidth usage per hour

Average bandwidth usage per hour (A) is correct because establishing a normal throughput baseline per time interval lets the analyst spot deviations such as traffic spikes, data exfiltration, or denial-of-service conditions that exceed the expected range. Number of connections per host (C) is correct because connection counts per host reveal abnormal session behavior, such as scanning, beaconing, or worm propagation, that would stand out against the established norm. Geolocation of source IPs (B) is useful context for investigating suspicious traffic but is not itself a traffic-pattern metric for a baseline. MAC addresses of devices (D) are Layer 2 identifiers used for asset inventory or access control, not for measuring normal traffic patterns. CPU utilization of servers (E) is a host performance metric, not a network traffic baseline metric.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Average bandwidth usage per hour

    Why this is correct

    Average bandwidth usage per hour establishes a quantitative norm for traffic volume, so deviations such as sudden spikes or sustained drops become detectable against the baseline. It directly satisfies the stem's requirement for metrics that reveal anomalies in normal traffic patterns, complementing flow-based measures like protocol distribution or connection counts.

  • ✗

    Geolocation of source IPs

    Why it's wrong here

    Geolocation of source IPs is enrichment metadata, not a volumetric or behavioural baseline metric, so it cannot establish normal traffic patterns. It is tempting because geographic origin is genuinely useful for alert triage and blocking, but baselining requires measurable counts such as flow volume and protocol distribution.

  • ✓

    Number of connections per host

    Why this is correct

    Tracking connections per host exposes deviations such as beaconing, port scanning or worm propagation, where a single endpoint suddenly opens far more sessions than its established norm. This metric satisfies the stem's requirement for a baseline that flags anomalous traffic volume, complementing flow-level counters rather than relying on payload inspection.

  • ✗

    MAC addresses of devices

    Why it's wrong here

    MAC addresses are static hardware identifiers that do not vary with traffic behaviour, so they cannot form a baseline of normal patterns. It is tempting because MAC addresses support asset inventory and rogue-device detection, but anomaly detection baselines require dynamic traffic metrics.

  • ✗

    CPU utilization of servers

    Why it's wrong here

    CPU is a system metric, not network.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.