Courseiva
Security Monitoring →hardMultiple Select

200-201 Security Monitoring Practice Question

A SOC analyst is correlating multiple data sources after a suspected web application compromise on an internet-facing server. The analyst has access to web server logs, firewall logs, and endpoint detection and response (EDR) telemetry. Which TWO log sources or record types would most directly help identify the initial exploitation attempt and the subsequent post-exploitation activity? (Choose two.)

⚠ Common exam trap

The trap here is selecting network-layer sources such as firewall logs because they sound comprehensive, when identifying exploitation and post-exploitation activity requires application-layer and endpoint-level telemetry.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Web server access logs containing HTTP request methods, URIs, status codes, and user-agent strings

Web server access logs expose the initial malicious HTTP request and its parameters, while EDR process and command-line telemetry reveals the resulting execution on the host, such as spawned shells or web shell activity. Together they connect the attack vector to post-exploitation behavior. Firewall, DHCP, and interface statistics provide useful context but lack the application and endpoint detail required to attribute and reconstruct the intrusion.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Web server access logs containing HTTP request methods, URIs, status codes, and user-agent strings

    Why this is correct

    Web server access logs record each request's method, URI, status code, and user-agent, making them the primary source for spotting exploitation attempts such as SQL injection, path traversal, or command injection in request parameters. They reveal the initial attack vector and timing, which anchors the rest of the investigation. Correlating these entries with endpoint activity identifies the exploited process and any spawned child processes.

  • ✗

    DHCP lease logs from the corporate network

    Why it's wrong here

    DHCP lease logs map MAC addresses to assigned IP addresses over time, which is useful for attributing activity to a device on an internal network. For an internet-facing server with a static address, these logs add little. They do not capture application requests or process execution, so they cannot identify the exploitation attempt or the subsequent post-exploitation behavior on the server.

  • ✓

    EDR process creation and command-line telemetry from the web server host

    Why this is correct

    EDR process creation and command-line telemetry reveals what executed after exploitation, such as a web server spawning cmd.exe, PowerShell, or a web shell interpreter. This directly exposes post-exploitation activity including reconnaissance, persistence, and lateral movement tooling. Pairing these events with web access logs ties the initial request to the resulting process tree, giving a complete attack narrative.

  • ✗

    Firewall logs showing allowed and denied connections between the internet and the DMZ

    Why it's wrong here

    Firewall logs show connection-level metadata such as source and destination IPs, ports, and allow or deny decisions. They help establish whether an external host reached the server and when, but they cannot show the application-layer payload that constitutes the exploitation attempt. Without web or endpoint detail, firewall logs alone cannot distinguish a malicious request from legitimate traffic.

  • ✗

    Switch port mirroring statistics showing interface utilization

    Why it's wrong here

    Interface utilization statistics show bandwidth consumption on switch ports and can hint at large transfers, but they contain no request, process, or user context. They cannot distinguish exploitation traffic from normal load or identify which commands ran after compromise. This data is useful for capacity planning and volumetric anomalies, not for reconstructing the exploitation sequence.

Visual reference

Client DHCP Server 1 Discover (broadcast) 2 Offer (IP: 192.168.1.10) 3 Request (I accept) 4 Acknowledge (lease confirmed) DORA — the four-step DHCP lease process

About these practice questions

One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.