Courseiva
mediumMultiple SelectObjective-mapped

200-201 Practice Question: A security policy mandates that all network…

A security policy mandates that all network devices must have logging enabled and that logs must be reviewed regularly. Which TWO practices are essential for effective log review?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Aggregating logs from all devices into a central server.

Central aggregation (option A) and automated analysis with correlation tools (option C) are essential for effective log review because they enable efficient monitoring and quick identification of security incidents. Aggregation consolidates logs from multiple sources, while automated analysis helps detect patterns and anomalies that manual review would miss. Storage duration (option D) and common format (option E) are supporting practices but not core to the review process itself. Reactive review (option B) is ineffective because logs must be reviewed proactively.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Aggregating logs from all devices into a central server.

    Why this is correct

    Centralization enables comprehensive analysis and correlation across the network.

  • Reviewing logs only when an incident occurs.

    Why it's wrong here

    Effective review is proactive and continuous, not just reactive.

  • Automated log analysis with correlation tools.

    Why this is correct

    Automation helps identify patterns and anomalies that manual review would miss.

  • Storing logs for at least one year.

    Why it's wrong here

    Storage duration is about retention, not the review process itself.

  • Ensuring logs are in a common format like Syslog.

    Why it's wrong here

    Common format aids parsing but is not essential for review; aggregation tools can normalize.

About these practice questions

This 200-201 question is part of Courseiva's 979-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.