nerdexam
Cisco

200-201 · Question #346

Refer to the exhibit. A security analyst received a ticket about suspicious traffic from one of the workstations. During the investigation, the analyst discovered that the workstation is communicating

The correct answer is B. Traffic is not encrypted. E. HTTP requests and responses are sent in plaintext.. The security analyst faces challenges in investigating further because the unencrypted and plaintext nature of the traffic, while visible, requires deeper analysis or specialized tools beyond the L1's current capabilities.

Submitted by eva_at· Mar 6, 2026Network Intrusion Analysis

Question

Refer to the exhibit. A security analyst received a ticket about suspicious traffic from one of the workstations. During the investigation, the analyst discovered that the workstation is communicating with an external IP The analyst was not able to investigate further and escalated the case to a T2 security analyst. What are the two data visibility challenges that the security analyst should identify? (Choose two.)

Exhibit

200-201 question #346 exhibit

Options

  • AA default user agent is present in the headers.
  • BTraffic is not encrypted.
  • CEncrypted data is being transmitted.
  • DPOST requests have a "Microsoft-IIS/7.5" server header.
  • EHTTP requests and responses are sent in plaintext.

How the community answered

(43 responses)
  • A
    23% (10)
  • B
    56% (24)
  • C
    7% (3)
  • D
    14% (6)

Why each option

The security analyst faces challenges in investigating further because the unencrypted and plaintext nature of the traffic, while visible, requires deeper analysis or specialized tools beyond the L1's current capabilities.

AA default user agent is present in the headers.

A default user agent is a specific header detail, not a general data visibility challenge preventing further investigation of the entire traffic flow.

BTraffic is not encrypted.Correct

Traffic being unencrypted presents a visibility challenge for an L1 analyst as they might lack the tools or expertise to efficiently parse and contextualize large volumes of raw, unencrypted data for deeper investigation, requiring escalation.

CEncrypted data is being transmitted.

Encrypted data *would* be a significant visibility challenge, but the correct answers indicate the opposite state (unencrypted/plaintext).

DPOST requests have a "Microsoft-IIS/7.5" server header.

A specific server header ("Microsoft-IIS/7.5") is a detail visible within the traffic, not a general challenge to the overall visibility of the data.

EHTTP requests and responses are sent in plaintext.Correct

HTTP requests and responses sent in plaintext can be a data visibility challenge because, while the data is readable, effectively analyzing large volumes of such data to identify malicious patterns or specific content often requires advanced tooling or skills beyond an L1's scope, hindering further investigation.

Concept tested: Network traffic analysis challenges for analysts

Topics

#encrypted traffic#network visibility#incident response#network analysis challenges

Community Discussion

No community discussion yet for this question.

Full 200-201 Practice