Courseiva
Security Monitoring →mediumMultiple Select

200-201 Security Monitoring Practice Question

A security analyst is tuning a SIEM to detect lateral movement. Which THREE log sources would provide the most useful data for this purpose? (Choose THREE.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Windows Event Logs showing network connections and process creation.

Option A is correct because Windows Event Logs such as Security Event ID 4688 (process creation) and Sysmon Event ID 3 (network connection) reveal suspicious process-to-network relationships that are hallmarks of lateral movement tools like PsExec or Cobalt Strike. Option D is correct because system logs capturing authentication events (e.g., Windows 4624/4625, Linux sshd and sudo entries) across multiple hosts expose pass-the-hash, credential reuse, and remote logon patterns central to lateral movement. Option E is correct because firewall logs showing internal-to-internal connections (east-west traffic) highlight anomalous host-to-host communication that would otherwise be invisible at the perimeter. Option B is not appropriate because web server logs for external requests focus on inbound client activity against a service, not host-to-host movement inside the network. Option C is not appropriate because DNS logs for external domain queries are more useful for command-and-control and exfiltration detection than for identifying lateral movement between internal hosts.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Windows Event Logs showing network connections and process creation.

    Why this is correct

    Windows Event Logs capture process creation (Sysmon Event ID 1) and network connection events (Event ID 3), exposing the parent-child process chains and outbound connections lateral movement tools generate. This directly satisfies the SIEM tuning requirement by supplying host-level telemetry that reveals anomalous execution and remote connection patterns across endpoints.

  • ✗

    Web server logs for external requests.

    Why it's wrong here

    Web server logs record inbound HTTP requests to published services, not authentication or session activity between internal hosts, so they cannot reveal lateral movement. They are tempting because they expose exploitation attempts against internet-facing applications, which suits detecting initial access rather than east-west traversal.

  • ✗

    DNS logs for external domain queries.

    Why it's wrong here

    DNS logs for external domain queries capture resolution of internet names, not internal host-to-host connections, so they miss lateral movement between internal systems. They are tempting because they detect command-and-control beaconing and DNS tunnelling, which addresses exfiltration rather than east-west traversal.

  • ✓

    System logs showing authentication events across hosts.

    Why this is correct

    System logs capturing authentication events across hosts expose the credential use that lateral movement depends on, such as type 3 network logons and remote service authentications recorded in the Security channel. This satisfies the stem's requirement for detecting movement between hosts, since each hop generates a fresh authentication on the target machine.

  • ✓

    Firewall logs showing connections between internal hosts.

    Why this is correct

    Firewall logs record allowed and denied connections between internal hosts, exposing host-to-host traffic patterns that reveal lateral movement. This satisfies the requirement for internal east-west visibility, since perimeter devices log the source, destination and port pairs used during pivoting.

About these practice questions

Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.