nerdexam
Cisco

200-201 · Question #202

Refer to the exhibit. An engineer received an event log file to review. Which technology generated the log?

The correct answer is C. firewall. The exhibit, showing logs of allowed or denied connections with source/destination IPs and ports, is characteristic of a firewall's logging output.

Submitted by obi.ng· Mar 6, 2026Network Intrusion Analysis

Question

Refer to the exhibit. An engineer received an event log file to review. Which technology generated the log?

Exhibit

200-201 question #202 exhibit

Options

  • ANetFlow
  • Bproxy
  • Cfirewall
  • DIDS/IPS

How the community answered

(54 responses)
  • A
    6% (3)
  • B
    7% (4)
  • C
    67% (36)
  • D
    20% (11)

Why each option

The exhibit, showing logs of allowed or denied connections with source/destination IPs and ports, is characteristic of a firewall's logging output.

ANetFlow

NetFlow logs focus on network flow statistics (e.g., volume, duration) rather than individual packet allow/deny decisions by security rules.

Bproxy

Proxy logs primarily detail web requests and responses handled by the proxy server, not general network connection activity across various protocols.

CfirewallCorrect

Firewall logs commonly record details about network connection attempts, including source and destination IP addresses, ports, protocols, and whether the traffic was permitted or blocked, aligning with the type of event log described.

DIDS/IPS

IDS/IPS logs typically focus on security alerts, detected threats, and signatures, rather than comprehensive logging of all connection states (allowed/denied).

Concept tested: Identifying firewall log entries

Source: https://learn.microsoft.com/en-us/azure/firewall/firewall-logs-metrics

Topics

#log analysis#firewall logs#network devices#event correlation

Community Discussion

No community discussion yet for this question.

Full 200-201 Practice