Courseiva
Security Monitoring →hardMultiple Choice

200-201 Security Monitoring Practice Question

An analyst is triaging an alert generated by Cisco Secure Network Analytics (Stealthwatch) showing a host inside the network communicating with a known command-and-control IP. The analyst wants to determine whether the communication has already resulted in data theft. Which additional telemetry source would provide the most direct evidence of successful exfiltration?

⚠ Common exam trap

The trap here is equating detection of command-and-control contact with proof of data theft; contact alone shows a channel exists, while flow byte counts are what demonstrate that data actually moved across it.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

NetFlow records showing outbound byte volume from the internal host to the C2 address.

Confirming exfiltration requires evidence of data actually leaving the network. NetFlow byte counters toward the command-and-control address provide that measurement directly and can be compared against the host's normal egress baseline. Signature updates, DHCP leases, and authentication events are useful for context and attribution but cannot quantify outbound transfer volume, so they do not answer whether theft occurred.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    DHCP lease logs showing the internal host renewed its IP address.

    Why it's wrong here

    DHCP lease information only maps an IP address to a MAC address and lease duration, which is useful for attribution but not for measuring data movement. It cannot reveal whether files were transferred to the command-and-control server. Using lease logs here addresses host identification, not the exfiltration question the analyst is actually trying to resolve.

  • ✓

    NetFlow records showing outbound byte volume from the internal host to the C2 address.

    Why this is correct

    NetFlow volume counters directly quantify how much data left the internal host toward the command-and-control address. A large, sustained outbound byte count relative to the host's normal baseline is the most direct flow-level indicator that data was actually transferred rather than merely attempted. This makes it the strongest evidence of successful exfiltration among the available telemetry sources.

  • ✗

    Authentication logs showing the user logged into the host via RDP.

    Why it's wrong here

    Authentication logs establish who accessed the host and when, which supports lateral movement or initial access analysis. They do not measure outbound data volume or confirm that information was stolen. This evidence could help build a timeline of the intrusion, but it cannot directly demonstrate that exfiltration to the C2 address succeeded.

  • ✗

    Syslog entries from the host's antivirus agent showing a signature update occurred.

    Why it's wrong here

    Antivirus signature updates are routine maintenance events and say nothing about whether data left the network. They neither confirm nor deny exfiltration and would only establish that the endpoint's protection is current. Relying on this source would not answer the analyst's question about data theft and would consume triage time without producing relevant evidence.

Visual reference

Client DHCP Server 1 Discover (broadcast) 2 Offer (IP: 192.168.1.10) 3 Request (I accept) 4 Acknowledge (lease confirmed) DORA — the four-step DHCP lease process

About these practice questions

This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.