200-201 Security Monitoring Practice Question
A security analyst observes a NetFlow record showing a single internal IP communicating with many external IPs on port 445 within seconds. This pattern is indicative of:
⚠ Common exam trap
200-201 often tests the distinction between a port scan (many ports, few hosts) and service scanning (one port, many hosts) — candidates default to 'port scan' whenever they see many connections, missing that the single-port fan-out indicates SMB service enumeration.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
SMB scanning
A single internal host contacting many external IPs on TCP/445 in a short window is the signature of SMB scanning — the host is enumerating SMB services across the internet or a target range. Port 445 is the SMB-over-TCP port, and the fan-out to many destinations distinguishes scanning from a single-target connection. This is often a precursor to SMB exploitation (EternalBlue, SMBGhost) or lateral movement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
DNS tunneling
Why it's wrong here
DNS tunneling uses port 53.
- ✗
Data exfiltration
Why it's wrong here
Exfiltration moves data outward from internal hosts to a small set of external destinations, usually over established channels such as HTTPS or DNS, generating sustained outbound volume. This record shows rapid connections to many external hosts on port 445, which is scanning behaviour, not bulk transfer. Exfiltration would show fewer destinations and larger transferred byte counts.
- ✓
SMB scanning
Why this is correct
SMB scanning matches the record precisely: port 445 is SMB, and one internal host contacting many external IPs within seconds indicates horizontal sweeps seeking exposed file shares. The high fan-out and short timeframe satisfy the stem's beaconing-free, rapid connection pattern, distinguishing it from single-target exploitation or data transfer.
- ✗
Port scan
Why it's wrong here
A port scan typically sends SYN or probe packets across many destination ports on one or few hosts, seeking open services; this record shows one port across many external hosts, the inverse pattern. It is tempting because both involve rapid, numerous connections. The distinguishing axis is fan-out across ports versus fan-out across hosts.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.