200-201 Network Intrusion Analysis Practice Question
A network analyst is reviewing firewall logs and sees repeated inbound connections from a single external IP to TCP port 445 on multiple internal hosts over a short period. The connections are followed by SMB negotiation attempts. Which activity does this most likely represent?
⚠ Common exam trap
The trap here is treating any SMB traffic as normal file sharing and ignoring that the source is external and the targets are numerous.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
SMB enumeration or exploitation attempts against internal file-sharing services
Inbound SMB connections to TCP port 445 from one external IP across many internal hosts indicate enumeration or exploitation of file-sharing services. Backup traffic, legitimate VPN-based file access, and DNS zone transfers have different source, port, and pattern characteristics. The sweep across multiple hosts in a short time is the key indicator of malicious SMB activity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A backup server replicating data to internal hosts
Why it's wrong here
Backup replication would typically originate from an internal, trusted server and target a consistent set of hosts on a schedule. An external IP hitting many internal hosts on port 445 in a short window is inconsistent with routine backup traffic. Backup traffic would also follow established authentication and not look like repeated negotiation attempts.
- ✗
DNS zone transfer requests to internal DNS servers
Why it's wrong here
DNS zone transfers use TCP port 53, not 445, and target DNS servers rather than file-sharing hosts. The observed SMB negotiation is unrelated to DNS. This option confuses a name-resolution service with the SMB file-sharing service, so it cannot explain the traffic.
- ✓
SMB enumeration or exploitation attempts against internal file-sharing services
Why this is correct
Repeated inbound connections to TCP 445 across multiple hosts, followed by SMB negotiation, indicate an external actor probing or attacking SMB services. Port 445 is used by SMB for file sharing and is a common target for enumeration and exploitation. The breadth of targets suggests scanning or worm-like behavior rather than a single targeted connection.
- ✗
Normal SMB file access by remote employees using VPN
Why it's wrong here
Remote employees would connect through a VPN concentrator, and the source IP in firewall logs would be the VPN gateway or an internal address, not an arbitrary external IP. Normal file access also targets specific shares and users rather than sweeping many hosts. The pattern of many hosts in a short period is not typical of legitimate remote access.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.