200-201 Security Monitoring Practice Question
A network security analyst is reviewing NetFlow records from a perimeter router and observes that an internal server at 172.16.5.20 has transferred approximately 4.5 GB to an external IP address in country X over the past three hours, all during non-business hours. The destination IP has no prior communication history with the organization and the traffic uses port 443. Which analysis approach would best confirm whether this represents data exfiltration?
⚠ Common exam trap
The trap here is treating volumetric NetFlow evidence as sufficient proof of exfiltration, when confirming the exfiltration of data requires inspecting the content or metadata of the transfer itself.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Capture full packet data for the transfer and perform content inspection to identify the data being sent
To confirm exfiltration, the analyst must determine what data is leaving, not just how much. Full packet capture with content inspection, or decrypted proxy and TLS logs where available, reveals file types, protocols, and payloads. NetFlow establishes the anomaly—large volume, unusual destination, off-hours timing—but content-level visibility converts suspicion into confirmation and supports incident response decisions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Check the router's interface error counters for packet loss
Why it's wrong here
Interface error counters indicate physical or link-layer problems such as CRC errors and drops, which are unrelated to whether data is being exfiltrated. High error counts would suggest network health issues, not malicious data transfer. This check does not address the content, destination reputation, or intent behind the outbound traffic and would not confirm exfiltration.
- ✗
Review the server's antivirus scan history for the past week
Why it's wrong here
Antivirus scan history shows whether known malware signatures were detected on the server, but it does not describe what data left the network or where it went. Exfiltration can occur using legitimate tools and living-off-the-land binaries that antivirus may not flag. While useful as supporting context, scan history alone cannot confirm whether the 4.5 GB transfer represents stolen data.
- ✗
Verify the server's operating system patch level
Why it's wrong here
Patch level indicates exposure to known vulnerabilities but says nothing about whether an active transfer contains stolen data. An unpatched server could be a risk factor, yet patching status cannot confirm the nature of traffic already observed. This action belongs to vulnerability management and does not provide the content-level evidence required to validate exfiltration.
- ✓
Capture full packet data for the transfer and perform content inspection to identify the data being sent
Why this is correct
Full packet capture with content inspection can reveal the actual payload, file types, and protocols involved in the transfer, confirming whether sensitive data is leaving the network. NetFlow alone shows volume and endpoints but not content. Capturing and inspecting the traffic, or using proxy and TLS inspection logs where decryption is possible, provides the definitive evidence needed to confirm exfiltration.
Go deeper
Related to this question
About these practice questions
One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.