Courseiva
mediumMultiple Select

200-201 Practice Question: Which TWO of the following are valid sources of…

Which TWO of the following are valid sources of security monitoring data in a Cisco security architecture?

⚠ Common exam trap

Cisco often tests the distinction between data sources used for security monitoring (Syslog, NetFlow) versus management or authentication protocols (RADIUS, SNMP, WMI), leading candidates to confuse RADIUS accounting or SNMP traps as valid monitoring inputs.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Syslog messages

Syslog messages (C) are a core source of security monitoring data because network devices, firewalls, and IPS/IDS appliances forward event, error, and audit messages to a central syslog collector or SIEM for correlation and alerting. NetFlow records (E) provide flow-level metadata (source/destination IP, ports, protocol, byte/packet counts, timestamps) that enable traffic profiling, anomaly detection, and threat hunting in a Cisco security architecture. RADIUS accounting (A) is primarily used for user session accounting and billing/AAA purposes rather than as a general security monitoring telemetry source. SNMP traps (B) are mainly for device health and fault management, not security event monitoring. WMI queries (D) are a Windows management mechanism and are not a standard Cisco security monitoring data source.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    RADIUS accounting

    Why it's wrong here

    RADIUS accounting records authentication and session usage for network access control, not security event telemetry fed to monitoring. It is tempting because AAA logs feel security-relevant, and RADIUS would be the correct source when auditing user login sessions or billing network access time.

  • ✗

    SNMP traps

    Why it's wrong here

    SNMP traps deliver device health, interface and threshold alerts, not security event data. They are tempting because network devices generate them continuously and they feed network management platforms; SNMP would be the right source for link-down or CPU-threshold monitoring, not for security monitoring.

  • ✓

    Syslog messages

    Why this is correct

    Syslog messages are a standard telemetry source, carrying device and application events into a Cisco security architecture for correlation. Firewall and IDS platforms emit syslog, making it a valid monitoring input alongside NetFlow and endpoint telemetry.

  • ✗

    WMI queries

    Why it's wrong here

    WMI queries collect Windows host inventory and performance counters, not the network and endpoint telemetry Cisco security monitoring consumes. It is tempting because WMI exposes rich endpoint detail, and it would be correct for Windows configuration or patch-state auditing rather than feeding a Cisco security architecture.

  • ✓

    NetFlow records

    Why this is correct

    NetFlow records export flow-level metadata — source and destination IPs, ports, protocol and byte counts — from routers and switches, providing the network telemetry that Cisco security monitoring architectures consume alongside logs and IPS events.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.