200-201 Security Monitoring Practice Question
An analyst reviews Cisco ASA syslog messages and sees repeated entries with message ID 106023 denied inbound TCP from an external address to an internal web server on port 443. The web server is expected to receive inbound HTTPS traffic. What should the analyst investigate?
⚠ Common exam trap
The trap here is assuming any inbound denial is an attack, when an expected service being denied indicates a firewall ACL problem that affects legitimate users.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Whether the access control list is blocking legitimate inbound HTTPS
ASA syslog 106023 is generated when a packet is denied by an ACL. Because the internal web server is expected to accept inbound HTTPS, the repeated denials on port 443 point to an ACL that is preventing legitimate traffic. The analyst should inspect the interface ACL and object groups to confirm the web server's public address is permitted, treating this as an availability issue first.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Whether the ASA is failing over to the standby unit
Why it's wrong here
Failover events generate their own syslog messages, such as 105001 or 105003, and are not represented by 106023. Message 106023 is a per-packet ACL denial and does not indicate a high-availability state change. Investigating failover status would not explain why inbound TCP to port 443 is being dropped. The analyst should correlate with ACL configuration and interface status, not with failover logs that describe a different class of event.
- ✗
Whether the external address is a known malicious scanner
Why it's wrong here
While the external address could be a scanner, the scenario states that the web server is expected to receive inbound HTTPS traffic. The denial affects any client, including legitimate users, because the ACL is blocking port 443. Treating the event purely as a scanning attempt ignores the availability impact on the intended service. The analyst should first determine whether the ACL is correct, then evaluate the source reputation if the traffic is unexpected.
- ✗
Whether the web server has a valid TLS certificate installed
Why it's wrong here
A certificate problem would not generate ASA message 106023, which is specifically an ACL denial at the packet-filtering stage. The connection never reached the web server, so TLS negotiation and certificate validation never occurred. Investigating the certificate would be irrelevant to the logged event. The analyst should focus on why the firewall dropped the packet, not on application-layer configuration that only matters after the packet is permitted through the interface.
- ✓
Whether the access control list is blocking legitimate inbound HTTPS
Why this is correct
Message 106023 indicates that a packet was denied by an ACL, and the destination port 443 with an expected inbound service strongly suggests a misconfigured or overly restrictive ACL. The analyst should review the interface ACL and any object group references to confirm whether the web server's public address is permitted. If the server is meant to receive HTTPS from the internet, the denial represents an availability issue rather than an attack, and the ACL must be corrected.
Visual reference
About these practice questions
This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.