easyMultiple Choice
200-201 Practice Question: A security analyst notices a sudden spike in…
A security analyst notices a sudden spike in NetFlow data from a single workstation to multiple external IP addresses on port 443. What is the most likely explanation for this traffic pattern?
⚠ Common exam trap
Cisco often tests the misconception that any HTTPS traffic is benign, but the trap here is that a sudden spike in outbound HTTPS flows from a single source to many external IPs is abnormal and indicates data exfiltration, not normal web browsing.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Potential data exfiltration
A single workstation sending a sudden spike of NetFlow data to multiple external IP addresses on port 443 (HTTPS) is a classic indicator of data exfiltration. Attackers often encrypt stolen data in HTTPS tunnels to evade detection, and the abrupt increase in outbound connections to many distinct external hosts is not typical of normal user behavior. NetFlow records showing a high volume of flows from one source to many destinations on the same port strongly suggest an automated process, such as a data theft tool, rather than legitimate traffic.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Internal network scanning
Why it's wrong here
Internal scanning targets RFC1918 addresses within the local network, whereas this traffic fans out to multiple external IP addresses. It is tempting because scanning also produces many connections, but the destinations here are public, indicating command-and-control or exfiltration.
- ✗
Normal web browsing activity
Why it's wrong here
Routine browsing contacts a handful of CDNs, not a sustained fan-out to many external addresses on 443. It is tempting because 443 is HTTPS, yet the volume and breadth of destinations indicate beaconing or exfiltration rather than human web use.
- ✓
Potential data exfiltration
Why this is correct
Outbound connections to many external hosts on port 443, with a sharp NetFlow volume increase, match data exfiltration over HTTPS: stolen data is tunnelled through encrypted web traffic to attacker-controlled endpoints, evading content inspection. The single-workstation-to-multiple-destinations fan-out distinguishes it from normal browsing or a single command-and-control channel.
- ✗
A scheduled software update
Why it's wrong here
Scheduled updates normally contact a small set of vendor or CDN endpoints, not many unrelated external addresses simultaneously. It is tempting because updates generate HTTPS traffic, but the fan-out pattern and sudden onset point to beaconing rather than a managed patch cycle.
Go deeper
Related to this question
About these practice questions
This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.