Courseiva
Security Monitoring →mediumMultiple Choice

200-201 Security Monitoring Practice Question

A network security analyst is reviewing NetFlow records from a perimeter router and observes that an internal server at 172.16.5.20 has transferred approximately 4.5 GB to an external IP address in country X over the past three hours, all during non-business hours. The destination IP has no prior communication history with the organization and the traffic uses port 443. Which analysis approach would best confirm whether this represents data exfiltration?

⚠ Common exam trap

The trap here is treating volumetric NetFlow evidence as sufficient proof of exfiltration, when confirming the exfiltration of data requires inspecting the content or metadata of the transfer itself.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Capture full packet data for the transfer and perform content inspection to identify the data being sent

To confirm exfiltration, the analyst must determine what data is leaving, not just how much. Full packet capture with content inspection, or decrypted proxy and TLS logs where available, reveals file types, protocols, and payloads. NetFlow establishes the anomaly—large volume, unusual destination, off-hours timing—but content-level visibility converts suspicion into confirmation and supports incident response decisions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Check the router's interface error counters for packet loss

    Why it's wrong here

    Interface error counters indicate physical or link-layer problems such as CRC errors and drops, which are unrelated to whether data is being exfiltrated. High error counts would suggest network health issues, not malicious data transfer. This check does not address the content, destination reputation, or intent behind the outbound traffic and would not confirm exfiltration.

  • ✗

    Review the server's antivirus scan history for the past week

    Why it's wrong here

    Antivirus scan history shows whether known malware signatures were detected on the server, but it does not describe what data left the network or where it went. Exfiltration can occur using legitimate tools and living-off-the-land binaries that antivirus may not flag. While useful as supporting context, scan history alone cannot confirm whether the 4.5 GB transfer represents stolen data.

  • ✗

    Verify the server's operating system patch level

    Why it's wrong here

    Patch level indicates exposure to known vulnerabilities but says nothing about whether an active transfer contains stolen data. An unpatched server could be a risk factor, yet patching status cannot confirm the nature of traffic already observed. This action belongs to vulnerability management and does not provide the content-level evidence required to validate exfiltration.

  • ✓

    Capture full packet data for the transfer and perform content inspection to identify the data being sent

    Why this is correct

    Full packet capture with content inspection can reveal the actual payload, file types, and protocols involved in the transfer, confirming whether sensitive data is leaving the network. NetFlow alone shows volume and endpoints but not content. Capturing and inspecting the traffic, or using proxy and TLS inspection logs where decryption is possible, provides the definitive evidence needed to confirm exfiltration.

About these practice questions

One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.