200-201 Security Monitoring Practice Question
Which log type would an analyst examine to view details about HTTP methods (GET, POST), response codes, and user-agent strings?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Web server logs
Web server logs record HTTP requests and responses, including methods, URLs, response codes, and user-agent information.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Web server logs
Why this is correct
Web server logs record each HTTP request, capturing the method (GET, POST), status code and User-Agent header, so they directly satisfy the stem's requirement for those three fields. Other log types, such as firewall or authentication logs, lack this application-layer detail.
- ✗
System logs
Why it's wrong here
System logs capture operating-system and service events such as process starts, authentication, and kernel messages; they contain no HTTP request metadata. Web or proxy logs record methods, status codes, and user-agent strings. System logs are the right source for host-level troubleshooting, not web traffic analysis.
- ✗
Firewall logs
Why it's wrong here
Firewall logs record permitted or denied connections by source, destination, port, and action; they do not parse application-layer HTTP fields. Methods, response codes, and user-agent strings appear in web server or proxy logs. Firewall logs suit network access investigations, not HTTP transaction detail.
- ✗
DNS logs
Why it's wrong here
DNS logs record queries, resolved names, record types, and client addresses; they never contain HTTP methods, status codes, or user-agent strings. Those fields belong to web or proxy logs. DNS logs are the correct source for domain resolution and tunnelling investigations, not HTTP request analysis.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.