Courseiva
Security Monitoring →hardMultiple Choice

200-201 Security Monitoring Practice Question

In Zeek (Bro), which log file would an analyst examine to identify HTTP methods, URIs, and response codes from web traffic?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

http.log

Zeek's http.log contains detailed HTTP transaction information including methods, URIs, and status codes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    files.log

    Why it's wrong here

    files.log records file transfers and hashes extracted from protocols such as HTTP, not request metadata. It is tempting because HTTP carries files, but methods, URIs and response codes live in http.log, which parses those request and response fields directly.

  • ✗

    dns.log

    Why it's wrong here

    dns.log records DNS queries, responses and record types, not web request metadata. It is tempting because resolving a hostname precedes an HTTP request, but methods, URIs and status codes are parsed by the HTTP analyser and written to http.log.

  • ✗

    conn.log

    Why it's wrong here

    conn.log captures connection-level tuples such as source and destination IP, port, protocol and duration, without application-layer detail. It is tempting because HTTP traffic appears there as connections, but methods, URIs and response codes require the protocol analyser in http.log.

  • ✓

    http.log

    Why this is correct

    The http.log records HTTP transactions, capturing request methods, URIs, host headers, response status codes and user agents. This directly satisfies the stem's requirement to identify HTTP methods, URIs and response codes from web traffic, whereas conn.log, dns.log and ssl.log lack application-layer HTTP detail.

About these practice questions

This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.