Courseiva
Security Monitoring →mediumMultiple Choice

200-201 Security Monitoring Practice Question

A security analyst observes a NetFlow record showing a single internal IP communicating with many external IPs on port 445 within seconds. This pattern is indicative of:

⚠ Common exam trap

200-201 often tests the distinction between a port scan (many ports, few hosts) and service scanning (one port, many hosts) — candidates default to 'port scan' whenever they see many connections, missing that the single-port fan-out indicates SMB service enumeration.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

SMB scanning

A single internal host contacting many external IPs on TCP/445 in a short window is the signature of SMB scanning — the host is enumerating SMB services across the internet or a target range. Port 445 is the SMB-over-TCP port, and the fan-out to many destinations distinguishes scanning from a single-target connection. This is often a precursor to SMB exploitation (EternalBlue, SMBGhost) or lateral movement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    DNS tunneling

    Why it's wrong here

    DNS tunneling uses port 53.

  • ✗

    Data exfiltration

    Why it's wrong here

    Exfiltration moves data outward from internal hosts to a small set of external destinations, usually over established channels such as HTTPS or DNS, generating sustained outbound volume. This record shows rapid connections to many external hosts on port 445, which is scanning behaviour, not bulk transfer. Exfiltration would show fewer destinations and larger transferred byte counts.

  • ✓

    SMB scanning

    Why this is correct

    SMB scanning matches the record precisely: port 445 is SMB, and one internal host contacting many external IPs within seconds indicates horizontal sweeps seeking exposed file shares. The high fan-out and short timeframe satisfy the stem's beaconing-free, rapid connection pattern, distinguishing it from single-target exploitation or data transfer.

  • ✗

    Port scan

    Why it's wrong here

    A port scan typically sends SYN or probe packets across many destination ports on one or few hosts, seeking open services; this record shows one port across many external hosts, the inverse pattern. It is tempting because both involve rapid, numerous connections. The distinguishing axis is fan-out across ports versus fan-out across hosts.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.