200-201 Security Monitoring Practice Question
An analyst is using Zeek to monitor network traffic. Which THREE types of logs can Zeek generate to provide visibility into application-layer activity?
⚠ Common exam trap
Cisco often tests the distinction between network-layer logs (conn.log) and application-layer logs (http.log, dns.log, smtp.log), and candidates may incorrectly assume conn.log covers application-layer activity because it includes port numbers.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
smtp.log
Zeek generates smtp.log (B) to record SMTP transactions, including sender/recipient envelopes, subjects, and mail server responses, giving application-layer visibility into email traffic. dns.log (D) captures DNS queries and responses at the application layer, logging query names, record types, and answers. http.log (E) records HTTP requests and replies, including methods, URIs, host headers, user agents, and status codes, which is classic application-layer visibility. conn.log (A) is a transport/network-layer connection summary (IPs, ports, protocol, bytes, duration) and does not describe application-layer activity, while weird.log (C) logs protocol anomalies and unexpected behavior rather than normal application-layer transactions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
conn.log
Why it's wrong here
conn.log summarises transport-layer connections — addresses, ports, duration and byte counts — without decoding application payloads. It is the correct source for flow-level inventory and beaconing analysis, but application-layer visibility requires protocol-specific logs such as http.log, dns.log or smtp.log.
- ✓
smtp.log
Why this is correct
Zeek's SMTP analyser parses email transactions at the application layer, producing smtp.log with fields such as sender, recipient, subject and helo, satisfying the requirement for application-layer visibility. It captures protocol-level mail activity rather than transport metadata, so it directly evidences application-layer behaviour in the monitored traffic.
- ✗
weird.log
Why it's wrong here
weird.log records protocol anomalies and unexpected field values that Zeek's analysers flag, not normal application-layer transactions. It is the right log when investigating malformed or non-compliant protocol behaviour, whereas application visibility comes from http.log, dns.log or ssl.log.
- ✓
dns.log
Why this is correct
Zeek's DNS analyser decodes queries and responses into dns.log, recording queried names, record types, answers and response codes. This provides the application-layer visibility the stem requires, revealing name resolution activity that raw packet capture alone would not summarise.
- ✓
http.log
Why this is correct
Zeek's HTTP analyser reconstructs requests and replies into http.log, logging methods, URIs, host headers, user agents and status codes. This delivers the application-layer visibility the scenario demands, exposing web activity rather than just transport-layer flow data.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.