mediumMultiple SelectObjective-mapped
200-201 Practice Question: A network security monitoring analyst is…
A network security monitoring analyst is analyzing firewall logs and sees the following traffic: Source IP 10.1.1.50 to Destination IP 203.0.113.5 on port 443, protocol TCP, with a large amount of data transferred in both directions during business hours. The analyst suspects data exfiltration. Which TWO additional indicators would most strongly support this suspicion? (Choose two.)
⚠ Common exam trap
Cisco often tests the misconception that any encrypted traffic or high data transfer is automatically suspicious, when in fact the context of the certificate type and communication history is what distinguishes malicious exfiltration from legitimate business use.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The traffic uses TLS encryption with a self-signed certificate.
A self-signed TLS certificate is often used by attackers to encrypt exfiltrated data without the overhead of obtaining a legitimate certificate from a trusted CA. Legitimate services typically use certificates signed by a recognized CA, so a self-signed certificate in traffic to an external IP on port 443 is a strong indicator of malicious activity, especially when combined with large data transfers.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The traffic uses TLS encryption with a self-signed certificate.
Why this is correct
Self-signed certificates in data transfers can indicate attempts to hide exfiltration.
- ✗
The destination IP belongs to a cloud storage provider commonly used for backups.
Why it's wrong here
Legitimate backup traffic is not suspicious.
- ✗
The data transfer rate is consistently high for several hours.
Why it's wrong here
High bandwidth alone could be legitimate large file transfers.
- ✗
The destination port is used by a well-known web service.
Why it's wrong here
Well-known services are expected.
- ✓
The source IP has never communicated with this destination IP before.
Why this is correct
New communication patterns can indicate anomalous behavior.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-201 question from scratch — 979 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.