Courseiva

200-201 Network Intrusion Analysis Practice Question

A network analyst is reviewing firewall logs and sees repeated inbound connections from a single external IP to TCP port 445 on multiple internal hosts over a short period. The connections are followed by SMB negotiation attempts. Which activity does this most likely represent?

⚠ Common exam trap

The trap here is treating any SMB traffic as normal file sharing and ignoring that the source is external and the targets are numerous.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

SMB enumeration or exploitation attempts against internal file-sharing services

Inbound SMB connections to TCP port 445 from one external IP across many internal hosts indicate enumeration or exploitation of file-sharing services. Backup traffic, legitimate VPN-based file access, and DNS zone transfers have different source, port, and pattern characteristics. The sweep across multiple hosts in a short time is the key indicator of malicious SMB activity.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A backup server replicating data to internal hosts

    Why it's wrong here

    Backup replication would typically originate from an internal, trusted server and target a consistent set of hosts on a schedule. An external IP hitting many internal hosts on port 445 in a short window is inconsistent with routine backup traffic. Backup traffic would also follow established authentication and not look like repeated negotiation attempts.

  • ✗

    DNS zone transfer requests to internal DNS servers

    Why it's wrong here

    DNS zone transfers use TCP port 53, not 445, and target DNS servers rather than file-sharing hosts. The observed SMB negotiation is unrelated to DNS. This option confuses a name-resolution service with the SMB file-sharing service, so it cannot explain the traffic.

  • ✓

    SMB enumeration or exploitation attempts against internal file-sharing services

    Why this is correct

    Repeated inbound connections to TCP 445 across multiple hosts, followed by SMB negotiation, indicate an external actor probing or attacking SMB services. Port 445 is used by SMB for file sharing and is a common target for enumeration and exploitation. The breadth of targets suggests scanning or worm-like behavior rather than a single targeted connection.

  • ✗

    Normal SMB file access by remote employees using VPN

    Why it's wrong here

    Remote employees would connect through a VPN concentrator, and the source IP in firewall logs would be the VPN gateway or an internal address, not an arbitrary external IP. Normal file access also targets specific shares and users rather than sweeping many hosts. The pattern of many hosts in a short period is not typical of legitimate remote access.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.