Courseiva
Security Monitoring →mediumMultiple Choice

200-201 Security Monitoring Practice Question

An analyst sees a Snort alert with the message 'ET POLICY Outbound connection to known malicious IP'. What does this indicate?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

An internal host is connecting to an IP that is on a threat intelligence blacklist.

Snort signature-based IDS alerts on matching rules. This alert indicates a connection from an internal host to a known malicious IP address, likely a command-and-control server.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A malicious IP is connecting to an internal host.

    Why it's wrong here

    The signature states outbound, meaning an internal host initiated a connection to the malicious address, so the direction is reversed. The rule name describes traffic leaving the monitored network. Inbound connections from a known-bad IP would generate an inbound-direction alert instead.

  • ✗

    The firewall blocked the connection.

    Why it's wrong here

    Snort is an intrusion-detection system here; it generates the alert but takes no blocking action, so the connection may have succeeded. Blocking requires inline IPS mode or a separate firewall rule. This option would fit a scenario where an IPS or firewall log confirms a denied session.

  • ✓

    An internal host is connecting to an IP that is on a threat intelligence blacklist.

    Why this is correct

    The signature name identifies an outbound connection from an internal host to an IP address listed on a threat intelligence blacklist, indicating possible command-and-control or data exfiltration traffic. The rule triggers on the destination reputation, not on payload content, so it flags the connection itself as suspicious.

  • ✗

    The connection is encrypted and safe.

    Why it's wrong here

    The alert flags an outbound session to an address on a threat-intelligence blocklist, which says nothing about whether that traffic is encrypted; TLS would hide payload contents but the destination reputation remains the indicator that fired. Encryption is what a protocol such as HTTPS provides for confidentiality in transit, so a rule matching on destination IP reputation would still trigger regardless.

About these practice questions

This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.