Courseiva
Security Monitoring →hardMultiple Choice

200-201 Security Monitoring Practice Question

An analyst is configuring a Snort rule to detect a known exploit targeting Apache web servers. The exploit sends a malicious HTTP POST request with a long User-Agent string. Which Snort rule header and options are most appropriate?

⚠ Common exam trap

The trap is that candidates focus on the payload content ('POST', User-Agent regex) and overlook the protocol and port in the rule header — a rule with the right content but wrong protocol (ICMP/UDP) or wrong port (443) will never fire on the actual exploit traffic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

alert tcp any any -> any 80 (content:"POST"; pcre:"/User-Agent:.{200,}/R"; sid:1000001;)

The rule must alert on TCP traffic to port 80 because HTTP POST requests use TCP, and Apache web servers typically listen on port 80 for unencrypted HTTP. The content match for 'POST' and the PCRE regex looking for a User-Agent string of 200 or more characters correctly targets the described exploit. This combination of protocol, port, and payload inspection is the most appropriate Snort rule.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    alert icmp any any -> any 80 (content:"POST"; pcre:"/User-Agent:.{200,}/R"; sid:1000001;)

    Why it's wrong here

    The header specifies ICMP, so the rule never inspects TCP port 80 traffic carrying the HTTP POST; Snort matches the protocol in the header before evaluating content. ICMP rules suit ping or ICMP-based covert-channel detection, not HTTP exploit signatures.

  • ✗

    alert tcp any any -> any 443 (content:"POST"; pcre:"/User-Agent:.{200,}/R"; sid:1000001;)

    Why it's wrong here

    The exploit targets Apache web servers over HTTP port 80, but this rule inspects TCP port 443, so it misses the traffic entirely. It is tempting because the tcp protocol, POST content match and long User-Agent regex are otherwise correct, and the rule would work for HTTPS traffic on 443.

  • ✓

    alert tcp any any -> any 80 (content:"POST"; pcre:"/User-Agent:.{200,}/R"; sid:1000001;)

    Why this is correct

    The rule alerts on TCP port 80, matching the HTTP POST, and the pcre option detects a User-Agent exceeding 200 characters, which is the exploit's signature. The content match on POST plus the regex satisfies the requirement to detect this Apache-targeting request.

  • ✗

    alert udp any any -> any 80 (content:"GET"; pcre:"/User-Agent:.{200,}/R"; sid:1000001;)

    Why it's wrong here

    The exploit uses HTTP POST over TCP, but this rule specifies the udp protocol and matches content "GET", so it cannot detect the POST request. It is tempting because port 80 and the long User-Agent regex are correct, and the rule would work for a GET-based attack over TCP.

About these practice questions

One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.