mediumMultiple SelectObjective-mapped
200-201 Practice Question: Which THREE of the following are key elements of…
Which THREE of the following are key elements of a security monitoring and analysis strategy? (Choose three.)
⚠ Common exam trap
Cisco often tests the misconception that security monitoring can be purely network-focused or fully automated, but the correct approach requires a balanced, multi-source strategy with human oversight and continuous tuning.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Establishing a feedback loop for continuous improvement
Establishing a feedback loop for continuous improvement (A) is a key element because security monitoring is not a static process; it requires iterative refinement based on lessons learned from incidents, false positives, and changes in the threat landscape. This loop ensures that detection rules, response playbooks, and monitoring configurations evolve to maintain effectiveness against new attack vectors and reduce noise over time.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Establishing a feedback loop for continuous improvement
Why this is correct
Continuous improvement adapts the monitoring to new threats and changing environments.
- ✗
Focusing only on network-based monitoring to reduce complexity
Why it's wrong here
A comprehensive strategy includes host, network, and user monitoring.
- ✓
Regularly tuning detection mechanisms to reduce false positives
Why this is correct
Tuning improves alert fidelity and analyst efficiency.
- ✗
Automating all incident response decisions to eliminate human error
Why it's wrong here
Automation should augment, not replace, human judgment, especially in complex incidents.
- ✓
Centralized log management and correlation across multiple sources
Why this is correct
Centralization enables cross-correlation and holistic visibility.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-201 question from scratch — 979 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.