nerdexam
Cisco

200-201 · Question #545

Refer to the exhibit. During an investigation of unauthorized data exfiltration from a company's network, these logs were collected. Which log entry would be considered the best evidence for proving…

The correct answer is A. web proxy log. The web proxy log directly shows the act of data exfiltration (a file upload to an external site) along with the exact time and user, making it the strongest evidence of how and when the data left the network.

Submitted by manish99· Mar 6, 2026Security Monitoring

Question

Refer to the exhibit. During an investigation of unauthorized data exfiltration from a company's network, these logs were collected. Which log entry would be considered the best evidence for proving the specific method and time of data exfiltration?

Exhibit

200-201 question #545 exhibit

Options

  • Aweb proxy log
  • Bdatabase access log
  • CVPN connection log
  • Demail server log

How the community answered

(23 responses)
  • A
    78% (18)
  • B
    13% (3)
  • C
    4% (1)
  • D
    4% (1)

Explanation

The web proxy log directly shows the act of data exfiltration (a file upload to an external site) along with the exact time and user, making it the strongest evidence of how and when the data left the network.

Topics

#data exfiltration#log analysis#web proxy logs#incident response

Community Discussion

No community discussion yet for this question.

Full 200-201 Practice