200-201 Security Monitoring Practice Question
A security engineer is setting up a Snort rule to detect FTP traffic where the source IP is not from the internal network. Which Snort rule header correctly specifies the action, protocol, source, and destination?
⚠ Common exam trap
200-201 often tests Snort header syntax, and candidates forget that ! negates the variable — they pick $HOME_NET thinking it means 'external' when it actually means 'internal,' or they choose UDP for FTP, which is TCP-only.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
alert tcp !$HOME_NET any -> any 21
The rule header alert tcp !$HOME_NET any -> any 21 correctly specifies: action (alert), protocol (tcp), source (!$HOME_NET, i.e., NOT the internal network), source port (any), direction (->), destination (any), and destination port (21, FTP). The ! negation operator inverts the HOME_NET variable, so the rule fires only when the source is external — exactly what the engineer wants.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
alert tcp !$HOME_NET any -> any 21
Why this is correct
The `!$HOME_NET` negation operator matches any source outside the defined internal network, satisfying the "not from the internal network" constraint. `alert tcp` sets the action and protocol, `any` covers all source ports, and `-> any 21` targets FTP destination port 21 on any host.
- ✗
alert tcp $HOME_NET any -> any 21
Why it's wrong here
This would alert on FTP traffic from internal IPs, the opposite of what is needed.
- ✗
alert tcp any any -> any 21
Why it's wrong here
This rule alerts on all FTP traffic, not just from external sources.
- ✗
alert udp any any -> any 21
Why it's wrong here
FTP uses TCP, not UDP.
Go deeper
Related to this question
About these practice questions
One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.