Courseiva
mediumMultiple Choice

200-201 Practice Question: In Security Onion, an analyst runs 'squert' and…

In Security Onion, an analyst runs 'squert' and sees a high number of alerts from a single source IP across multiple destination ports. What is the most likely cause?

⚠ Common exam trap

Cisco often tests the distinction between a port scan and a denial of service attack, where candidates mistakenly associate 'high number of alerts' with DoS, but the key differentiator is the single source IP targeting multiple destination ports versus overwhelming a single service.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Port scan

Squert is a web interface for Sguil in Security Onion that visualizes alert data from the intrusion detection system (IDS). A high number of alerts from a single source IP targeting multiple destination ports is a classic signature of a port scan, where the attacker probes a range of ports on one or more targets to discover open services. The IDS triggers multiple alerts because each probe (e.g., SYN packets to different ports) matches a detection rule, such as those for TCP SYN scans.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Denial of service

    Why it's wrong here

    A single source hitting many destination ports indicates horizontal port scanning, not a denial-of-service flood, which would show high volume against one or few ports. DoS is tempting because alert counts are high, but the distinguishing axis is destination-port spread, not packet rate.

  • ✗

    SQL injection

    Why it's wrong here

    SQL injection targets a web application's database queries and appears as anomalous HTTP requests to one service, not as one source IP touching many destination ports. It is tempting because both are attacks, but the port-spread signature indicates scanning, not application-layer injection.

  • ✓

    Port scan

    Why this is correct

    A single source IP contacting many destination ports in rapid succession matches the signature of a port scan, which Squert surfaces as numerous alerts across multiple destination ports. This satisfies the stem's pattern of one source hitting many ports.

  • ✗

    Phishing attack

    Why it's wrong here

    Phishing delivers malicious email or links to users; it does not generate network alerts from one source IP across many destination ports. It is tempting because phishing is a common initial-access vector, but the observed pattern is port scanning, which phishing telemetry would not produce.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.