Free 200-201 Exam Braindumps (page: 15)

Page 14 of 66

Refer to the exhibit.



Which type of log is displayed?

  1. IDS
  2. proxy
  3. NetFlow
  4. sys

Answer(s): A

Explanation:

You also see the 5-tuple in IPS events, NetFlow records, and other event data. In fact, on the exam you may need to differentiate between a firewall log versus a traditional IPS or IDS event. One of the things to remember is that traditional IDS and IPS use signatures, so an easy way to differentiate is by looking for a signature ID (SigID). If you see a signature ID, then most definitely the event is a traditional IPS or IDS event.



Refer to the exhibit.



What information is depicted?

  1. IIS data
  2. NetFlow data
  3. network discovery event
  4. IPS event data

Answer(s): B



What is the difference between the ACK flag and the RST flag in the NetFlow log session?

  1. The RST flag confirms the beginning of the TCP connection, and the ACK flag responds when the data for the payload is complete
  2. The ACK flag confirms the beginning of the TCP connection, and the RST flag responds when the data for the payload is complete
  3. The RST flag confirms the receipt of the prior segment, and the ACK flag allows for the spontaneous termination of a connection
  4. The ACK flag confirms the receipt of the prior segment, and the RST flag allows for the spontaneous termination of a connection

Answer(s): D



Refer to the exhibit.



Which type of log is displayed?

  1. proxy
  2. NetFlow
  3. IDS
  4. sys

Answer(s): B






Post your Comments and Discuss Cisco® 200-201 exam with other Community members:

200-201 Discussions & Posts