200-201 Security Monitoring Practice Question
A NetFlow report shows that host 10.0.0.5 has sent 1 GB of data to external IP 198.51.100.10 over port 443 in the last hour, while other hosts average 100 MB. This anomaly is most indicative of:
⚠ Common exam trap
Cisco often tests the distinction between 'volume anomalies' and 'connection anomalies'—the trap here is confusing a large data transfer (exfiltration) with a volumetric attack (like DDoS) or reconnaissance (like port scanning), when the key is the direction and volume of the traffic to a single external host.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Data exfiltration
The sudden, disproportionate egress of 1 GB of data from a single host to an external IP over port 443 (HTTPS) is a classic indicator of data exfiltration. While HTTPS traffic is common, the volume anomaly—10x the average of other hosts—suggests unauthorized copying of sensitive data, as attackers often use encrypted channels to blend in with normal traffic.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Port scan activity
Why it's wrong here
A port scan sends small SYN probes across many ports, generating kilobytes rather than 1 GB to a single destination on port 443. It is tempting because scans are reconnaissance against external hosts, yet their packet volume is far too low to match this report.
- ✗
Normal video streaming
Why it's wrong here
Streaming to one external IP over 443 is plausible, but 1 GB in an hour is only about 2.2 Mbps, far below typical video rates, and the host's tenfold deviation from peers marks it as anomalous. It is tempting because 443 carries legitimate encrypted media traffic.
- ✗
DNS amplification attack
Why it's wrong here
DNS amplification floods a victim with responses over port 53, not 443, and the traffic direction here is outbound from an internal host. It is tempting because amplification attacks also produce large traffic volumes, but they target the resolver's victim rather than an external server.
- ✓
Data exfiltration
Why this is correct
Sustained outbound transfer over port 443 to one external address, at ten times the peer baseline, indicates data leaving the network. Port 443 is commonly abused to blend with HTTPS traffic, and the volume deviation from other hosts satisfies the anomaly constraint in the stem.
Go deeper
Related to this question
About these practice questions
One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.