nerdexam
Cisco

200-201 · Question #242

When an event is investigated, which type of data provides the investigate capability to determine if data exfiltration has occurred?

The correct answer is A. full packet capture. Full packet capture provides the most detailed information, including actual data payloads, which is essential for confirming if specific sensitive data has been exfiltrated from a network.

Submitted by anjalisingh· Mar 6, 2026Network Intrusion Analysis

Question

When an event is investigated, which type of data provides the investigate capability to determine if data exfiltration has occurred?

Options

  • Afull packet capture
  • BNetFlow data
  • Csession data
  • Dfirewall logs

How the community answered

(54 responses)
  • A
    91% (49)
  • B
    2% (1)
  • C
    6% (3)
  • D
    2% (1)

Why each option

Full packet capture provides the most detailed information, including actual data payloads, which is essential for confirming if specific sensitive data has been exfiltrated from a network.

Afull packet captureCorrect

Full packet capture records every byte of data transmitted over the network, including the entire payload of packets. This comprehensive detail allows investigators to examine the exact content of communications, definitively determining if sensitive information has been improperly sent outside the network.

BNetFlow data

NetFlow data provides metadata about network traffic (source/destination IPs, ports, protocols, data volumes) but does not include the actual content of the packets, making it insufficient to confirm data exfiltration.

Csession data

Session data typically summarizes connection information and does not contain the packet payloads necessary to confirm the specific data exfiltrated.

Dfirewall logs

Firewall logs record connection attempts and policy actions but do not contain the payload of the packets, meaning they cannot reveal *what* data might have been exfiltrated.

Concept tested: Data types for exfiltration investigation

Source: https://www.cisco.com/c/en/us/products/security/network-visibility-security/what-is-full-packet-capture.html

Topics

#full packet capture#data exfiltration#forensics#network evidence

Community Discussion

No community discussion yet for this question.

Full 200-201 Practice