nerdexam
CompTIA

SY0-501 · Question #14

A security analyst is reviewing the following output from an IPS: Given this output, which of the following can be concluded? (Select TWO).

The correct answer is B. The source IP of the attack is coming from 250 19.18.71. C. The attacker sent a malformed IGAP packet, triggering the alert. The IPS output reveals that the attack originated from the IP address 250.19.18.71 and involved a malformed IGAP packet, which triggered the security alert.

Submitted by ngozi_ng· Mar 4, 2026Introduction to Security

Question

A security analyst is reviewing the following output from an IPS:

Given this output, which of the following can be concluded? (Select TWO).

Exhibit

SY0-501 question #14 exhibit

Options

  • AThe source IP of the attack is coming from 250.19 18.22.
  • BThe source IP of the attack is coming from 250 19.18.71.
  • CThe attacker sent a malformed IGAP packet, triggering the alert.
  • DThe attacker sent a malformed TCP packet, triggering the alert.
  • EThe TTL value is outside of the expected range, triggering the alert.

How the community answered

(27 responses)
  • A
    4% (1)
  • B
    81% (22)
  • D
    11% (3)
  • E
    4% (1)

Why each option

The IPS output reveals that the attack originated from the IP address 250.19.18.71 and involved a malformed IGAP packet, which triggered the security alert.

AThe source IP of the attack is coming from 250.19 18.22.

The IPS output would show 250.19.18.71, not 250.19.18.22, as the source IP address of the attack.

BThe source IP of the attack is coming from 250 19.18.71.Correct

The IPS alert details would explicitly list 'Source IP: 250.19.18.71', directly identifying this address as the originator of the detected malicious network traffic.

CThe attacker sent a malformed IGAP packet, triggering the alert.Correct

The IPS output would clearly indicate a 'Protocol: IGAP' and a 'Malformed Packet' signature or description, specifying that the alert was triggered by an improperly formatted IGAP packet.

DThe attacker sent a malformed TCP packet, triggering the alert.

The IPS alert specifies IGAP as the affected protocol; therefore, the attacker did not send a malformed TCP packet in this particular instance.

EThe TTL value is outside of the expected range, triggering the alert.

The IPS alert describes a 'malformed IGAP packet' as the trigger, not an unexpected TTL value, which is a distinct type of network anomaly.

Concept tested: Analyzing network intrusion logs for attack details

Source: https://www.cisco.com/c/en/us/td/docs/security/asa/asa93/configuration/firewall/asa-93-firewall-config/monitor-log.html

Topics

#IPS#log analysis#intrusion detection#IGAP

Community Discussion

No community discussion yet for this question.

Full SY0-501 Practice