Courseiva
easyMultiple Choice

200-201 Practice Question: Which best practice helps ensure accurate network…

Which best practice helps ensure accurate network intrusion analysis when reviewing logs from multiple sources?

⚠ Common exam trap

Cisco often tests the misconception that log format consistency is more important than time synchronization, but without synchronized time, even identical formats cannot provide accurate event correlation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use synchronized time across all devices.

Synchronized time (via NTP) ensures that logs from different sources share a consistent timestamp, which is critical for correlating events across network devices during intrusion analysis. Without time synchronization, an attacker's actions might appear out of order or be missed entirely, leading to inaccurate incident reconstruction.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use synchronized time across all devices.

    Why this is correct

    Correlating events across firewalls, IDS and hosts requires a common timeline; without synchronised clocks via NTP, packet timestamps drift between devices, making it impossible to reconstruct the true sequence of an intrusion and producing false conclusions about causality.

  • ✗

    Disable all logging except firewall logs.

    Why it's wrong here

    Discarding all sources except firewall logs removes the endpoint, proxy, and IDS telemetry needed to correlate an intrusion across the network. Firewall-only logging suits narrow perimeter reviews, but accurate multi-source analysis depends on retaining and correlating logs from every relevant device.

  • ✗

    Rely solely on automated analysis tools.

    Why it's wrong here

    Automated tools alone cannot correlate context across heterogeneous log sources, so subtle multi-stage intrusions evade detection without analyst validation. Tools are tempting because they scale triage and flag known signatures, and would suffice for high-volume, single-source alerting where human review is impractical.

  • ✗

    Store logs in different formats for each source.

    Why it's wrong here

    Mixed formats prevent automated correlation and normalisation across sources, forcing manual parsing that delays detection. Heterogeneous formats are acceptable when tools normalise them, but a common schema such as CEF or syslog is what enables accurate multi-source intrusion analysis.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.