nerdexam
Cisco

200-201 · Question #564

Refer to the exhibit. An analyst receives an IDS alert pertaining to a possible data exfiltration attempt. An additional set of logs is collected from different systems and analyzed. Which type of…

The correct answer is A. corroborative evidence. These logs come from other systems and help support or validate what the IDS reported by providing independent confirmation of related activity (such as allowed connections, authentication events, failed logon attempts, and observed data transfer), strengthening the case for…

Submitted by tunde_lagos· Mar 6, 2026Security Monitoring

Question

Refer to the exhibit. An analyst receives an IDS alert pertaining to a possible data exfiltration attempt. An additional set of logs is collected from different systems and analyzed. Which type of evidence do the logs provide in relation to the primary alert from the IDS?

Exhibit

200-201 question #564 exhibit

Options

  • Acorroborative evidence
  • Bprimary evidence
  • Ccircumstantial evidence
  • Dsecondary evidence

How the community answered

(34 responses)
  • A
    85% (29)
  • B
    9% (3)
  • C
    3% (1)
  • D
    3% (1)

Explanation

These logs come from other systems and help support or validate what the IDS reported by providing independent confirmation of related activity (such as allowed connections, authentication events, failed logon attempts, and observed data transfer), strengthening the case for the suspected exfiltration.

Topics

#evidence types#incident response#log analysis#IDS alerts

Community Discussion

No community discussion yet for this question.

Full 200-201 Practice