Courseiva
Security Monitoring →mediumMultiple Choice

200-201 Security Monitoring Practice Question

A security engineer is setting up a Snort rule to detect FTP traffic where the source IP is not from the internal network. Which Snort rule header correctly specifies the action, protocol, source, and destination?

⚠ Common exam trap

200-201 often tests Snort header syntax, and candidates forget that ! negates the variable — they pick $HOME_NET thinking it means 'external' when it actually means 'internal,' or they choose UDP for FTP, which is TCP-only.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

alert tcp !$HOME_NET any -> any 21

The rule header alert tcp !$HOME_NET any -> any 21 correctly specifies: action (alert), protocol (tcp), source (!$HOME_NET, i.e., NOT the internal network), source port (any), direction (->), destination (any), and destination port (21, FTP). The ! negation operator inverts the HOME_NET variable, so the rule fires only when the source is external — exactly what the engineer wants.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    alert tcp !$HOME_NET any -> any 21

    Why this is correct

    The `!$HOME_NET` negation operator matches any source outside the defined internal network, satisfying the "not from the internal network" constraint. `alert tcp` sets the action and protocol, `any` covers all source ports, and `-> any 21` targets FTP destination port 21 on any host.

  • ✗

    alert tcp $HOME_NET any -> any 21

    Why it's wrong here

    This would alert on FTP traffic from internal IPs, the opposite of what is needed.

  • ✗

    alert tcp any any -> any 21

    Why it's wrong here

    This rule alerts on all FTP traffic, not just from external sources.

  • ✗

    alert udp any any -> any 21

    Why it's wrong here

    FTP uses TCP, not UDP.

About these practice questions

One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.