200-201 Host-Based Analysis Practice Question
A security analyst is investigating a Linux server that is exhibiting unusual outbound network traffic. The analyst runs 'netstat -tulpn' and observes a listening service on TCP port 4444, but the process name is 'sshd'. The analyst knows that SSH normally listens on port 22. Which of the following is the most likely explanation for this finding?
⚠ Common exam trap
The trap here is assuming that a process with a familiar name like 'sshd' is benign, but attackers can easily rename their malicious binaries.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A backdoor or reverse shell is masquerading as the SSH daemon.
The presence of a service named 'sshd' listening on port 4444, especially with unusual outbound traffic, is a red flag for a backdoor or reverse shell. Attackers frequently use common ports like 4444 for command-and-control and name their processes after legitimate services to blend in. Legitimate SSH should listen on port 22 unless explicitly changed, and such a change would be documented.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The server is running an SSH honeypot on port 4444 to attract attackers.
Why it's wrong here
A honeypot would typically be a separate service, not the actual sshd process. Moreover, honeypots are usually deployed intentionally and would be known to the security team. The scenario describes unusual outbound traffic, which is not characteristic of a honeypot that primarily listens for inbound connections. This is less likely than a backdoor.
- ✓
A backdoor or reverse shell is masquerading as the SSH daemon.
Why this is correct
Attackers often name malicious processes after legitimate services like 'sshd' to avoid detection. Port 4444 is commonly used by Metasploit and other penetration testing tools for reverse shells. The combination of an unexpected port and a process name that does not match the expected behavior (SSH on port 22) strongly indicates a backdoor or reverse shell masquerading as sshd.
- ✗
The SSH daemon is configured to use port 4444 for SFTP transfers only.
Why it's wrong here
SFTP runs over SSH and would use the same port as SSH, not a separate port. There is no standard configuration where sshd listens on an additional port for SFTP. This explanation is technically incorrect and does not align with the observed behavior of a listening service on port 4444.
- ✗
The SSH daemon has been reconfigured to listen on port 4444 for security through obscurity.
Why it's wrong here
While changing the SSH port is a common hardening practice, it would typically be documented and would not be associated with unusual outbound traffic. Moreover, the process name 'sshd' could be spoofed, but if it were a legitimate reconfiguration, the analyst would likely find configuration files indicating the change. The scenario suggests malicious activity, not a benign configuration.
Go deeper
Related to this question
About these practice questions
One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.