Courseiva
hardMultiple Choice

200-201 Practice Question: A SOC team is implementing a security monitoring…

A SOC team is implementing a security monitoring solution for a cloud-based infrastructure. Which of the following is the most important consideration for effective monitoring?

⚠ Common exam trap

Cisco often tests the misconception that encryption or cost-saving measures are the top priority in monitoring, when in fact the foundational requirement is complete visibility through centralized logging.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Centralized logging from all cloud services and on-premises.

Centralized logging is the most important consideration because it provides a single, unified view of security events across all cloud services and on-premises infrastructure. Without aggregation, the SOC cannot correlate events, detect distributed attacks, or perform effective threat hunting. This aligns with the principle of 'visibility first' in security monitoring.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Centralized logging from all cloud services and on-premises.

    Why this is correct

    Effective monitoring requires correlating events across every environment; centralised logging from all cloud services and on-premises gives the SOC one aggregated source, enabling detection of lateral movement and cross-boundary attacks that siloed, per-service logs would miss.

  • ✗

    Encrypting all logs at rest.

    Why it's wrong here

    Encryption at rest protects stored logs from disclosure but does not affect whether malicious activity is detected, so it fails the monitoring objective. It tempts because it is a genuine security control; it would be correct where the requirement is regulatory confidentiality of retained log data.

  • ✗

    Reducing log retention to save cost.

    Why it's wrong here

    Cutting retention destroys the historical data investigators need for correlation and retrospective threat hunting, directly undermining monitoring. It tempts because cloud storage costs are real; it would be correct where logs are purely operational and no forensic or compliance requirement exists.

  • ✗

    Using only native cloud monitoring tools.

    Why it's wrong here

    Native tools alone cannot correlate activity across multi-cloud and on-premises sources, so the SOC loses the unified telemetry the scenario demands. They are tempting because they are free and pre-integrated, and would suffice for a single-provider estate with no third-party feeds.

About these practice questions

Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.