nerdexam
Cisco

200-201 · Question #509

Refer to the exhibit. An engineer must map these events to the source technology that generated the event logs. To which technology do the generated logs belong?

The correct answer is C. IPS. The logs indicate intrusion detection and prevention events, such as: - "Intrusion TCP.Split.Handshake blocked" - "Intrusion Snort.TCP.SACK.Option.DoS blocked" - "Default-Malicious-Code-Detection-By-Endpoint" These are signatures typically seen in Intrusion Prevention Systems…

Submitted by viktor_hu· Mar 6, 2026Security Monitoring

Question

Refer to the exhibit. An engineer must map these events to the source technology that generated the event logs. To which technology do the generated logs belong?

Exhibit

200-201 question #509 exhibit

Options

  • Aproxy
  • Bantivirus
  • CIPS
  • Dfirewall

How the community answered

(61 responses)
  • A
    3% (2)
  • B
    5% (3)
  • C
    82% (50)
  • D
    10% (6)

Explanation

The logs indicate intrusion detection and prevention events, such as: - "Intrusion TCP.Split.Handshake blocked" - "Intrusion Snort.TCP.SACK.Option.DoS blocked" - "Default-Malicious-Code-Detection-By-Endpoint" These are signatures typically seen in Intrusion Prevention Systems (IPS), which are designed to detect and mitigate attacks like TCP handshake manipulation and DoS attacks. The mention of Snort, a well-known open-source IPS, further confirms that these logs originate from an IPS system rather than a firewall, antivirus, or proxy.

Topics

#event logs#log analysis#IPS#security technologies

Community Discussion

No community discussion yet for this question.

Full 200-201 Practice