Courseiva
Security Monitoring →easyMultiple Choice

200-201 Security Monitoring Practice Question

Which log type would an analyst examine to view details about HTTP methods (GET, POST), response codes, and user-agent strings?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Web server logs

Web server logs record HTTP requests and responses, including methods, URLs, response codes, and user-agent information.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Web server logs

    Why this is correct

    Web server logs record each HTTP request, capturing the method (GET, POST), status code and User-Agent header, so they directly satisfy the stem's requirement for those three fields. Other log types, such as firewall or authentication logs, lack this application-layer detail.

  • ✗

    System logs

    Why it's wrong here

    System logs capture operating-system and service events such as process starts, authentication, and kernel messages; they contain no HTTP request metadata. Web or proxy logs record methods, status codes, and user-agent strings. System logs are the right source for host-level troubleshooting, not web traffic analysis.

  • ✗

    Firewall logs

    Why it's wrong here

    Firewall logs record permitted or denied connections by source, destination, port, and action; they do not parse application-layer HTTP fields. Methods, response codes, and user-agent strings appear in web server or proxy logs. Firewall logs suit network access investigations, not HTTP transaction detail.

  • ✗

    DNS logs

    Why it's wrong here

    DNS logs record queries, resolved names, record types, and client addresses; they never contain HTTP methods, status codes, or user-agent strings. Those fields belong to web or proxy logs. DNS logs are the correct source for domain resolution and tunnelling investigations, not HTTP request analysis.

About these practice questions

Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.