Courseiva
mediumMultiple ChoiceObjective-mapped

200-201 Practice Question: An analyst is reviewing Snort alerts and notices…

An analyst is reviewing Snort alerts and notices repeated 'ET SCAN Potential SSH Scan' alerts from the same source IP. Which action should the analyst take next?

⚠ Common exam trap

Cisco often tests the principle that alerts must be validated with additional data sources (like logs) before taking action, trapping candidates who jump to blocking or ignoring based on the alert alone.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Correlate with authentication logs to confirm unsuccessful attempts.

Snort alerts for 'ET SCAN Potential SSH Scan' indicate a pattern of connection attempts to the SSH port (TCP/22), but the alert alone does not confirm whether the attempts were successful or malicious. Correlating with authentication logs (e.g., /var/log/auth.log or Windows Event ID 4625) allows the analyst to verify failed login attempts, which is the definitive evidence of an actual SSH brute-force attack. This step aligns with the network intrusion analysis methodology of validating alerts before taking action.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Correlate with authentication logs to confirm unsuccessful attempts.

    Why this is correct

    This provides evidence of actual brute force attempts, enabling informed decision-making.

  • Run a vulnerability scan on the destination.

    Why it's wrong here

    Vulnerability scanning is reactive and not the immediate next step for a potential scan.

  • Ignore because it is a false positive.

    Why it's wrong here

    Alerts should be investigated; ignoring may miss a real threat.

  • Immediately block the IP on the firewall.

    Why it's wrong here

    Blocking without verification could disrupt legitimate traffic and is not a standard first step.

About these practice questions

One of 979 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.