200-201 Security Monitoring Practice Question
A security analyst is using Zeek to analyze network traffic. Which Zeek log would be most useful for identifying HTTP requests to a known malicious domain?
⚠ Common exam trap
The trap is selecting dns.log because it shows domain lookups, but the question asks for HTTP requests, which are only fully captured in http.log; candidates must distinguish between resolution and actual request.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
http.log
Zeek's http.log records all HTTP requests and responses, including the host header, URI, method, and user agent. To identify HTTP requests to a known malicious domain, the http.log is the most direct source because it contains the destination host and URL. Analysts can search this log for the malicious domain in the 'host' or 'uri' fields.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
http.log
Why this is correct
Zeek's http.log records HTTP request metadata including the Host header and URI, so requests to a known malicious domain are directly visible there. conn.log lacks application-layer detail, and dns.log only captures name resolution, not the subsequent HTTP request itself.
- ✗
ssl.log
Why it's wrong here
ssl.log captures TLS handshake metadata such as SNI and certificate details, so plaintext HTTP requests to the domain never appear there. It is tempting because SNI can reveal a destination hostname, and ssl.log would be correct if the traffic were HTTPS rather than unencrypted HTTP.
- ✗
conn.log
Why it's wrong here
conn.log summarises IP flows with addresses, ports and byte counts, but contains no HTTP method, URI or Host header. It is tempting because connection records can correlate a client to a destination IP, and conn.log would be the right choice for mapping network sessions rather than inspecting application-layer requests.
- ✗
dns.log
Why it's wrong here
dns.log records resolver queries and responses, so it shows lookups of the malicious domain but not the HTTP request itself. It is tempting because DNS logging exposes the domain being contacted, and it would be the right choice if the question asked which log reveals name resolution activity.
Go deeper
Related to this question
About these practice questions
This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.