nerdexam
Cisco

200-201 · Question #538

Refer to the exhibit. A security engineer receives several alerts from the SNORT IPS/IDS reporting malicious traffic. What should the engineer understand by examining the SNORT logs?

The correct answer is C. A remote threat performs an EternalBlue attack on several hosts and different ports. The SNORT alerts show EternalBlue (MS17-010) exploitation attempts coming from an internal host (192.168.200.10) targeting a Windows system (192.168.2.101) specifically on port 445, which is the SMB port exploited by EternalBlue.

Submitted by anna_se· Mar 6, 2026Network Intrusion Analysis

Question

Refer to the exhibit. A security engineer receives several alerts from the SNORT IPS/IDS reporting malicious traffic. What should the engineer understand by examining the SNORT logs?

Exhibit

200-201 question #538 exhibit

Options

  • AA remote threat performs an EternalBlue attack on a Windows system on several ports.
  • BAn inside threat performs an EternalBlue attack on hosts 192.168.2.101 and 192.168.200.10 on
  • CA remote threat performs an EternalBlue attack on several hosts and different ports.
  • DAn inside threat performs an EternalBlue attack on a Windows system on port 445.

How the community answered

(57 responses)
  • A
    5% (3)
  • B
    19% (11)
  • C
    68% (39)
  • D
    7% (4)

Explanation

The SNORT alerts show EternalBlue (MS17-010) exploitation attempts coming from an internal host (192.168.200.10) targeting a Windows system (192.168.2.101) specifically on port 445, which is the SMB port exploited by EternalBlue.

Topics

#SNORT#IPS/IDS#Network intrusion#EternalBlue exploit#Alert analysis

Community Discussion

No community discussion yet for this question.

Full 200-201 Practice