mediumMultiple Choice
200-201 Practice Question: In Security Onion, an analyst runs 'squert' and…
In Security Onion, an analyst runs 'squert' and sees a high number of alerts from a single source IP across multiple destination ports. What is the most likely cause?
⚠ Common exam trap
Cisco often tests the distinction between a port scan and a denial of service attack, where candidates mistakenly associate 'high number of alerts' with DoS, but the key differentiator is the single source IP targeting multiple destination ports versus overwhelming a single service.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Port scan
Squert is a web interface for Sguil in Security Onion that visualizes alert data from the intrusion detection system (IDS). A high number of alerts from a single source IP targeting multiple destination ports is a classic signature of a port scan, where the attacker probes a range of ports on one or more targets to discover open services. The IDS triggers multiple alerts because each probe (e.g., SYN packets to different ports) matches a detection rule, such as those for TCP SYN scans.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Denial of service
Why it's wrong here
A single source hitting many destination ports indicates horizontal port scanning, not a denial-of-service flood, which would show high volume against one or few ports. DoS is tempting because alert counts are high, but the distinguishing axis is destination-port spread, not packet rate.
- ✗
SQL injection
Why it's wrong here
SQL injection targets a web application's database queries and appears as anomalous HTTP requests to one service, not as one source IP touching many destination ports. It is tempting because both are attacks, but the port-spread signature indicates scanning, not application-layer injection.
- ✓
Port scan
Why this is correct
A single source IP contacting many destination ports in rapid succession matches the signature of a port scan, which Squert surfaces as numerous alerts across multiple destination ports. This satisfies the stem's pattern of one source hitting many ports.
- ✗
Phishing attack
Why it's wrong here
Phishing delivers malicious email or links to users; it does not generate network alerts from one source IP across many destination ports. It is tempting because phishing is a common initial-access vector, but the observed pattern is port scanning, which phishing telemetry would not produce.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.