200-201 Security Monitoring Practice Question
A network baseline shows that a server typically sends 1-2 MB of data per hour to external IPs. Suddenly, the server sends 50 MB of data to an IP in a foreign country within 10 minutes. The traffic is encrypted. Which monitoring tool would best confirm data exfiltration?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
NetFlow/IPFIX analysis comparing current traffic to baseline
NetFlow/IPFIX provides flow records with byte counts, enabling detection of unusual data volumes, even with encrypted payloads.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
NetFlow/IPFIX analysis comparing current traffic to baseline
Why this is correct
NetFlow/IPFIX records flow metadata — source, destination, byte counts and timestamps — letting the analyst compare the 50 MB foreign transfer against the 1-2 MB hourly baseline. Encryption hides payload contents, but flow volume and destination still confirm exfiltration.
- ✗
Snort IDS with a rule to detect large file transfers
Why it's wrong here
Snort signatures match packet contents or headers; encrypted payloads defeat content rules, and volume thresholds are not reliably expressible as signatures. It is tempting because IDS rules can flag large transfers, but Snort is the correct choice when detecting known plaintext attack patterns rather than confirming encrypted exfiltration.
- ✗
Wireshark packet capture with a display filter for the destination IP
Why it's wrong here
The traffic is encrypted, so a Wireshark capture filtered on the destination IP reveals only ciphertext and flow volume, not the exfiltrated content. It is tempting because packet capture confirms the transfer occurred, but it is the correct choice when payloads are unencrypted and protocol-level detail is needed.
- ✗
Windows Event Logs for file access
Why it's wrong here
Windows Event Logs record local file access, not outbound network volume or destination geography, so they cannot confirm exfiltration to a foreign IP. They are tempting because file-access auditing can reveal which files were read, but that is the correct choice only when investigating insider copying on the host itself.
Go deeper
Related to this question
About these practice questions
One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.