mediumMultiple Select
200-201 Practice Question: Which TWO of the following are valid sources of…
Which TWO of the following are valid sources of security monitoring data in a Cisco security architecture?
⚠ Common exam trap
Cisco often tests the distinction between data sources used for security monitoring (Syslog, NetFlow) versus management or authentication protocols (RADIUS, SNMP, WMI), leading candidates to confuse RADIUS accounting or SNMP traps as valid monitoring inputs.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Syslog messages
Syslog messages (C) are a core source of security monitoring data because network devices, firewalls, and IPS/IDS appliances forward event, error, and audit messages to a central syslog collector or SIEM for correlation and alerting. NetFlow records (E) provide flow-level metadata (source/destination IP, ports, protocol, byte/packet counts, timestamps) that enable traffic profiling, anomaly detection, and threat hunting in a Cisco security architecture. RADIUS accounting (A) is primarily used for user session accounting and billing/AAA purposes rather than as a general security monitoring telemetry source. SNMP traps (B) are mainly for device health and fault management, not security event monitoring. WMI queries (D) are a Windows management mechanism and are not a standard Cisco security monitoring data source.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
RADIUS accounting
Why it's wrong here
RADIUS accounting records authentication and session usage for network access control, not security event telemetry fed to monitoring. It is tempting because AAA logs feel security-relevant, and RADIUS would be the correct source when auditing user login sessions or billing network access time.
- ✗
SNMP traps
Why it's wrong here
SNMP traps deliver device health, interface and threshold alerts, not security event data. They are tempting because network devices generate them continuously and they feed network management platforms; SNMP would be the right source for link-down or CPU-threshold monitoring, not for security monitoring.
- ✓
Syslog messages
Why this is correct
Syslog messages are a standard telemetry source, carrying device and application events into a Cisco security architecture for correlation. Firewall and IDS platforms emit syslog, making it a valid monitoring input alongside NetFlow and endpoint telemetry.
- ✗
WMI queries
Why it's wrong here
WMI queries collect Windows host inventory and performance counters, not the network and endpoint telemetry Cisco security monitoring consumes. It is tempting because WMI exposes rich endpoint detail, and it would be correct for Windows configuration or patch-state auditing rather than feeding a Cisco security architecture.
- ✓
NetFlow records
Why this is correct
NetFlow records export flow-level metadata — source and destination IPs, ports, protocol and byte counts — from routers and switches, providing the network telemetry that Cisco security monitoring architectures consume alongside logs and IPS events.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
About these practice questions
One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.