200-201 • Practice Exam 55
Free 200-201 practice exam — 20 questions with explanations. Set 55. No signup required.
A SOC analyst is reviewing firewall logs and sees repeated outbound connections from an internal server to an external IP on TCP port 443, but the traffic is not TLS. Packet capture shows a custom binary protocol with periodic small keepalives. Which type of malicious activity is most consistent with these findings?
Choose an answer to begin — your selection is scored in the full session.
20 questions · instant feedback and full explanations after every question.