mediumMultiple Choice
200-201 Practice Question: A security administrator for a company with 500…
You are a security administrator for a company with 500 employees. The company uses a SIEM with basic correlation rules. Recently, the HR department reported that several employees received phishing emails with a link to a fake login page. The emails bypassed the spam filter. You want to detect if any employees clicked the link. You have access to web proxy logs, DNS logs, and endpoint antivirus logs. The phishing link is 'http://malicious-login.com/verify'. Which action should you take first to identify affected users?
⚠ Common exam trap
Cisco often tests the distinction between DNS resolution and actual HTTP request completion, tricking candidates into thinking DNS logs are sufficient to prove a user clicked a link, when in fact only web proxy logs confirm the full URL was requested.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Query the web proxy logs for HTTP requests containing the URL.
The web proxy logs record all HTTP requests made by clients, including the full URL path. Querying for 'http://malicious-login.com/verify' directly shows which employees clicked the link, because the proxy captures the exact destination and timestamp of each request. This is the most direct and reliable evidence of user interaction with the phishing link.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Run a vulnerability scan on all employee workstations.
Why it's wrong here
A vulnerability scan enumerates missing patches and misconfigurations on hosts; it never records which users browsed to 'malicious-login.com/verify', so it cannot identify affected staff. It is tempting because scanning is a familiar first response to a suspected compromise, and it would be correct when assessing exposure of unpatched services.
- ✗
Search DNS logs for queries to 'malicious-login.com'.
Why it's wrong here
DNS logs show only the resolution of 'malicious-login.com', not whether the '/verify' URL was fetched, so clickers cannot be distinguished from hosts that merely resolved the domain. It is tempting because DNS is often the earliest network artefact; it would be correct when hunting domain-generation-algorithm or command-and-control lookups.
- ✗
Search endpoint logs for any malware detections.
Why it's wrong here
Antivirus logs record file-based malware detections, but a credential-harvesting page on 'malicious-login.com/verify' delivers no payload, so nothing is logged. It is tempting because endpoint AV telemetry does reveal compromise in drive-by download scenarios; here the proxy logs hold the HTTP GET evidence.
- ✓
Query the web proxy logs for HTTP requests containing the URL.
Why this is correct
Web proxy logs record outbound HTTP requests, so querying them for the exact URL 'http://malicious-login.com/verify' directly identifies which internal hosts reached the fake login page. DNS logs only show resolution attempts, and antivirus logs would not capture the click, making proxy logs the fastest evidence of affected users.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.