200-201 Security Monitoring Practice Question
A network security analyst is reviewing NetFlow records from a Cisco router and notices a large number of flows from a single internal host to many external IP addresses on port 445. The flows are short, with small packet counts, and occur within a few minutes. Which type of activity is most likely occurring?
⚠ Common exam trap
The trap here is assuming port 445 traffic is always internal file sharing, but external fan-out on that port is a strong indicator of scanning or worm activity.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A worm or scanner attempting to propagate via SMB
The combination of a single internal host, many external destinations, port 445, and short flows over a brief period is a hallmark of SMB scanning or worm propagation. This behavior aims to find and infect vulnerable systems. Analysts should isolate the host and investigate for malware, as this fan-out pattern is not normal for legitimate SMB usage.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A peer-to-peer file sharing client
Why it's wrong here
P2P clients typically use dynamic ports and maintain longer connections with peers, not short flows to many IPs on port 445. SMB is not a P2P protocol. The traffic pattern of rapid, small connections to numerous external hosts is more indicative of scanning for vulnerable SMB services than file sharing.
- ✓
A worm or scanner attempting to propagate via SMB
Why this is correct
Port 445 is used by SMB. A single host connecting to many external IPs on that port in a short time with short flows is characteristic of a worm or scanner trying to find vulnerable SMB services. This pattern is typical of exploits like WannaCry or NotPetya, which scan and propagate. The high fan-out and small packet counts indicate scanning, not normal file sharing.
- ✗
A legitimate backup process to a cloud storage provider
Why it's wrong here
Backup traffic to a cloud provider would typically use a specific set of external IPs and ports like 443 or 22, and would involve larger, longer flows. Connecting to many different external IPs on port 445 is not normal for backups. The short, small flows also do not match the sustained throughput of a backup operation.
- ✗
A misconfigured application performing a port scan
Why it's wrong here
While a misconfigured application could scan, the specific use of port 445 and the high fan-out to external addresses strongly suggests malicious SMB scanning. A misconfiguration would more likely target internal subnets or a single service. The pattern of many external targets is deliberate and consistent with worm propagation, not an accident.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.