200-201 Network Intrusion Analysis Practice Question
A security analyst notices that an internal web server is receiving HTTP requests where the User-Agent string is identical across thousands of requests originating from a single external IP address, and each request targets a different URL path on the server. The requests occur at a rate of several hundred per second. Which activity does this pattern most likely represent?
⚠ Common exam trap
The trap here is dismissing high-volume web requests as harmless crawler traffic without checking the request rate, source diversity, and User-Agent consistency.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Automated directory brute-forcing or content discovery
The pattern of one external IP sending hundreds of requests per second to many different URL paths with a constant User-Agent is a classic signature of automated content discovery and directory brute-forcing. These tools enumerate paths to uncover hidden resources. Legitimate crawlers rate-limit and identify themselves, while CSRF and response splitting involve different traffic characteristics.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Automated directory brute-forcing or content discovery
Why this is correct
A single source sending hundreds of requests per second to many different URL paths with an identical User-Agent is characteristic of automated content discovery or directory brute-forcing tools. These tools enumerate paths to find hidden files or administrative interfaces. The high rate and fixed User-Agent distinguish it from normal user browsing or legitimate crawling.
- ✗
Web content scraping by a search engine crawler
Why it's wrong here
Legitimate crawlers typically identify themselves with a recognized User-Agent and obey robots.txt, and they usually rate-limit their requests. The extremely high request rate and the single source IP with a fixed User-Agent are more consistent with automated abuse than a well-behaved crawler. Crawlers also usually spread requests over time rather than hundreds per second.
- ✗
Cross-site request forgery against authenticated users
Why it's wrong here
CSRF involves tricking an authenticated user's browser into sending unauthorized requests, typically from a malicious page. The traffic would originate from the victim's client, not a single external IP hitting many paths at high rate. CSRF also does not produce thousands of distinct URL path requests from one source.
- ✗
HTTP response splitting attack
Why it's wrong here
HTTP response splitting manipulates response headers by injecting CRLF sequences into user input, and it is detected by malformed headers rather than by request volume. The scenario describes high-volume requests to many paths, which is not the signature of response splitting. Response splitting would not require thousands of distinct URL paths.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.