nerdexam
Cisco

200-201 · Question #294

Refer to the exhibit. Which technology produced the log?

The correct answer is B. IPS/IDS. The log entry, with its specific format like '[1:2009363:1] ET POLICY PE EXE or DLL download HTTP', is characteristic of an Intrusion Detection/Prevention System (IDS/IPS).

Submitted by takeshi77· Mar 6, 2026Network Intrusion Analysis

Question

Refer to the exhibit. Which technology produced the log?

Exhibit

200-201 question #294 exhibit

Options

  • Aantivirus
  • BIPS/IDS
  • Cfirewall
  • Dproxy

How the community answered

(40 responses)
  • A
    13% (5)
  • B
    80% (32)
  • C
    3% (1)
  • D
    5% (2)

Why each option

The log entry, with its specific format like '[1:2009363:1] ET POLICY PE EXE or DLL download HTTP', is characteristic of an Intrusion Detection/Prevention System (IDS/IPS).

Aantivirus

Antivirus software primarily performs endpoint scanning and remediation, not network traffic analysis and signature-based alerting in this format.

BIPS/IDSCorrect

The log format, specifically the `[GID:SID:REV]` notation (e.g., `[1:2009363:1]`) and the signature-based alert message 'ET POLICY PE EXE or DLL download HTTP', are hallmarks of an IDS/IPS like Snort or Suricata, which detect suspicious network activity based on predefined rules and signatures.

Cfirewall

Firewalls primarily enforce access control rules based on IP addresses, ports, and protocols, and do not typically generate detailed content-based policy alerts with specific signature IDs like those shown.

Dproxy

A proxy server mediates network connections and logs requests, but it does not generate these types of signature-driven security alerts indicative of threat detection.

Concept tested: Log analysis, IDS/IPS identification

Source: https://www.snort.org/documentation

Topics

#IDS/IPS#Security Logs#Intrusion Detection

Community Discussion

No community discussion yet for this question.

Full 200-201 Practice