nerdexam
Cisco

200-201 · Question #473

Refer to the exhibit. An engineer must use a 5-tuple approach to isolate a compromised host in a grouped set of logs. Which data must the engineer use?

The correct answer is A. 57813. The 5-tuple approach used for identifying network traffic includes: Source IP address: The IP address of the device sending the data. Destination IP address: The IP address of the device receiving the data. Source port: The port number on the sender's side used for the…

Submitted by khalil_dz· Mar 6, 2026Network Intrusion Analysis

Question

Refer to the exhibit. An engineer must use a 5-tuple approach to isolate a compromised host in a grouped set of logs. Which data must the engineer use?

Exhibit

200-201 question #473 exhibit

Options

  • A57813
  • B7c:5c:f8:9f:d1:fc
  • Cb4:2a:0e:f2:27:83
  • D66

How the community answered

(17 responses)
  • A
    82% (14)
  • B
    6% (1)
  • C
    12% (2)

Explanation

The 5-tuple approach used for identifying network traffic includes: Source IP address: The IP address of the device sending the data. Destination IP address: The IP address of the device receiving the data. Source port: The port number on the sender's side used for the communication. Destination port: The port number on the receiver's side (in this case, TCP 57813). Protocol: The protocol used in the communication (TCP in this case). Only 57813 is part of this 5-tuple (destination port number). Other options are not part of the 5-tuple, because 7c:5c:f8:9f:d1:fc and b4:2a:0e:f2:27:83 are MAC addresses, and 66 refers to the packet

Topics

#5-tuple#network forensics#packet analysis#log analysis

Community Discussion

No community discussion yet for this question.

Full 200-201 Practice