Courseiva
easyMultiple Select

200-201 Practice Question: Which TWO pieces of information are essential for…

Which TWO pieces of information are essential for an analyst to correlate when investigating an intrusion alert from a network-based sensor?

⚠ Common exam trap

Cisco often tests the distinction between operational data (IP addresses, timestamps) and irrelevant administrative or physical details, trapping candidates who confuse 'essential for correlation' with 'nice to have' or 'commonly known' information.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Source and destination IP addresses

Option B (Source and destination IP addresses) is correct because correlating the source and destination IPs lets the analyst identify the communicating hosts, pivot to related logs (firewall, NetFlow, IDS/IPS), and determine whether the traffic is internal-to-external, external-to-internal, or lateral movement. Option D (Timestamp of the alert) is correct because the timestamp enables time-based correlation across disparate data sources, which is essential for reconstructing the sequence of events and aligning the sensor alert with firewall, proxy, and endpoint logs. The unmarked options do not belong: cable color (A) and sensor brand (C) are irrelevant physical/vendor details that do not help correlate events, and the security team lead's name (E) is an administrative fact, not investigative data.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The color of the network cables

    Why it's wrong here

    Cable colour is physical-layer documentation with no bearing on correlating an intrusion alert; it cannot tie events to an attacker or victim. Analysts correlate source and destination IP addresses with timestamps. Cable colour would only assist a technician tracing a physical patching fault, not an analyst investigating network-based intrusion evidence.

  • ✓

    Source and destination IP addresses

    Why this is correct

    Source and destination IP addresses identify the communicating hosts, letting the analyst map the alert to specific endpoints and pivot to their logs. This correlation satisfies the stem's requirement to trace the intrusion's origin and target across network telemetry.

  • ✗

    The brand of the sensor

    Why it's wrong here

    Sensor branding carries no investigative value for correlating an intrusion alert; it neither identifies the attacker nor the affected asset. Analysts must correlate source and destination IP addresses with timestamps to reconstruct the event. Branding would matter only during procurement or vendor support escalation, not alert triage.

  • ✓

    Timestamp of the alert

    Why this is correct

    The alert timestamp anchors the event in time, enabling the analyst to correlate it with logs, flows and other sensor data from the same window. This temporal alignment is essential for reconstructing the intrusion sequence accurately.

  • ✗

    The name of the security team lead

    Why it's wrong here

    The security team lead's name is an organisational detail, not evidence linking alert data to an intrusion. Correlation requires matching source/destination IPs and timestamps across sensors and logs. Team-lead identity would be relevant only for escalation or accountability reporting, not for establishing what happened on the network.

About these practice questions

One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.