200-201 Security Monitoring Practice Question
A security analyst is reviewing firewall logs and notices that a workstation is making outbound connections to multiple external IP addresses on port 22 (SSH). The workstation is not authorized to use SSH for external connections. Which type of activity does this most likely indicate?
⚠ Common exam trap
The trap here is assuming that SSH traffic is always legitimate because it is encrypted; however, unauthorized SSH from a workstation can indicate malware or an attacker using it for covert channels.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The workstation is infected with malware attempting to establish SSH tunnels for data exfiltration or C2.
Unauthorized outbound SSH from a workstation to multiple external IPs is highly suspicious. Attackers and malware often use SSH for encrypted C2 channels or data exfiltration because it blends with legitimate traffic. The lack of authorization and multiple destinations reinforce this as malicious activity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The workstation is being used as a jump host for legitimate remote administration.
Why it's wrong here
Legitimate remote administration would typically be authorized and documented. The scenario states the workstation is not authorized for external SSH, so this activity is suspicious. Jump hosts are usually servers, not workstations, and would be configured intentionally.
- ✗
The workstation is synchronizing time with external NTP servers over port 22.
Why it's wrong here
NTP uses UDP port 123, not TCP port 22. SSH is on port 22, so this activity cannot be NTP synchronization. The use of port 22 indicates SSH traffic, which is not used for time synchronization.
- ✓
The workstation is infected with malware attempting to establish SSH tunnels for data exfiltration or C2.
Why this is correct
Unauthorized outbound SSH from a workstation to multiple external IPs is a strong indicator of malware using SSH for command and control or data exfiltration. Attackers often use SSH to blend in with legitimate traffic or to create encrypted tunnels.
- ✗
The workstation is performing a vulnerability scan against external hosts.
Why it's wrong here
Vulnerability scans typically target specific ports and would be authorized. The scenario indicates the workstation is not authorized for external SSH, and scanning would likely involve more than just port 22. This pattern is more consistent with malware.
Go deeper
Related to this question
About these practice questions
One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.