nerdexam
Cisco

200-201 · Question #186

Refer to the exhibit. An analyst received this alert from the Cisco ASA device, and numerous activity logs were produced. How should this type of evidence be categorized?

The correct answer is D. best. Alerts and activity logs directly from a Cisco ASA device are considered best evidence, as they are primary, original records generated by a security appliance.

Submitted by kev92· Mar 6, 2026Security Policies and Procedures

Question

Refer to the exhibit. An analyst received this alert from the Cisco ASA device, and numerous activity logs were produced. How should this type of evidence be categorized?

Options

  • Aindirect
  • Bcircumstantial
  • Ccorroborative
  • Dbest

How the community answered

(37 responses)
  • A
    3% (1)
  • C
    3% (1)
  • D
    95% (35)

Why each option

Alerts and activity logs directly from a Cisco ASA device are considered best evidence, as they are primary, original records generated by a security appliance.

Aindirect

Indirect evidence requires inferences to connect it to a fact, whereas ASA logs are direct recordings of events.

Bcircumstantial

Circumstantial evidence suggests a fact indirectly, unlike ASA logs which are direct records of security events.

Ccorroborative

Corroborative evidence supports or confirms other evidence, but ASA logs can stand as primary evidence on their own.

DbestCorrect

Best evidence refers to primary or original evidence, which has the highest probative value. Logs and alerts directly generated by a security device like a Cisco ASA are direct records of events and thus qualify as best evidence in incident response and forensics.

Concept tested: Types of digital evidence (Best Evidence)

Topics

#forensic evidence#log evidence#Cisco ASA#evidence categorization

Community Discussion

No community discussion yet for this question.

Full 200-201 Practice