nerdexam
Cisco

200-201 · Question #228

Refer to the exhibit. During the analysis of a suspicious scanning activity incident, an analyst discovered multiple local TCP connection events. Which technology provided these logs?

The correct answer is D. firewall. Logs detailing local TCP connection events, especially in the context of suspicious scanning activity, are typically generated by a firewall that monitors and controls network traffic.

Submitted by yasin.bd· Mar 6, 2026Network Intrusion Analysis

Question

Refer to the exhibit. During the analysis of a suspicious scanning activity incident, an analyst discovered multiple local TCP connection events. Which technology provided these logs?

Exhibit

200-201 question #228 exhibit

Options

  • Aantivirus
  • Bproxy
  • CIDS/IPS
  • Dfirewall

How the community answered

(36 responses)
  • A
    6% (2)
  • B
    3% (1)
  • C
    3% (1)
  • D
    89% (32)

Why each option

Logs detailing local TCP connection events, especially in the context of suspicious scanning activity, are typically generated by a firewall that monitors and controls network traffic.

Aantivirus

Antivirus software focuses on detecting and mitigating malicious software on endpoints and does not primarily generate logs of general network connection events.

Bproxy

Proxy servers log web-related traffic that passes through them, not all local TCP connection events across various ports and protocols.

CIDS/IPS

IDS/IPS systems primarily generate alerts and logs related to detected threats or anomalies, rather than comprehensive logs of all network connection events like a firewall.

DfirewallCorrect

Firewalls are designed to monitor, filter, and log network connection attempts, including local TCP connection events and suspicious scanning activities, making them the primary source for such logs.

Concept tested: Identifying firewall logs for connection events

Source: https://learn.microsoft.com/en-us/azure/firewall/firewall-logs-metrics

Topics

#log analysis#TCP connections#scanning activity#firewall logs

Community Discussion

No community discussion yet for this question.

Full 200-201 Practice