200-201 Security Monitoring Practice Question
A security analyst is investigating a potential security incident and needs to correlate events across multiple data sources. Which two Cisco CyberOps tools or features would provide network flow data and intrusion event details respectively? (Choose two.)
⚠ Common exam trap
Test-takers frequently confuse Cisco Umbrella's DNS logs with network flow data, or assuming ISE provides intrusion events, when each tool has a specific telemetry focus.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Cisco Stealthwatch for network flow analysis
Cisco Stealthwatch is purpose-built for network flow analysis using NetFlow and other telemetry, while Firepower Management Center is the central console for intrusion events from Firepower sensors. Together, they provide the flow and intrusion data needed to correlate a security incident. The other tools focus on DNS, identity, or endpoint, which are not the requested data types.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Cisco Stealthwatch for network flow analysis
Why this is correct
Cisco Stealthwatch collects NetFlow and other flow data to provide network visibility and detect anomalies. It is designed for network flow analysis, helping analysts identify unusual traffic patterns and potential threats. In this scenario, it would supply the network flow data needed to understand communication patterns.
- ✓
Cisco Firepower Management Center for intrusion event details
Why this is correct
Firepower Management Center (FMC) aggregates and displays intrusion events generated by Firepower sensors. It provides detailed information about triggered Snort rules, including packet captures and rule metadata. This makes it the appropriate tool to obtain intrusion event details for correlation.
- ✗
Cisco Identity Services Engine for authentication logs
Why it's wrong here
Cisco Identity Services Engine (ISE) manages network access control and provides authentication, authorization, and accounting (AAA) logs. It does not supply network flow data or intrusion event details. Its role is identity and access management, not flow or intrusion monitoring.
- ✗
Cisco Umbrella for DNS security
Why it's wrong here
Cisco Umbrella provides DNS-layer security and enforcement, blocking malicious domains. While it offers DNS logs, it does not provide network flow data or intrusion event details. Its primary focus is on DNS security, making it less relevant for the specific data types requested in this scenario.
- ✗
Cisco Advanced Malware Protection for endpoint
Why it's wrong here
Cisco Advanced Malware Protection (AMP) for Endpoint focuses on endpoint malware detection and response. It provides endpoint event data, not network flow data or intrusion event details. While valuable for endpoint investigations, it does not fulfill the network-centric data needs described in the scenario.
Go deeper
Related to this question
About these practice questions
This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.