200-201 Security Monitoring Practice Question
A SOC analyst is analyzing NetFlow data and notices a sudden spike in outbound traffic from a single internal host to an external IP address during non-business hours. The traffic volume is significantly higher than the baseline. Which suspicion is most likely?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Data exfiltration is occurring
A sudden increase in outbound traffic to a single external IP, especially outside business hours, often indicates data exfiltration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The host is running a backup to cloud storage
Why it's wrong here
Cloud backups usually run to known provider endpoints on a defined schedule and would appear across multiple hosts, not one host at an unusual hour. Backup traffic is the correct benign explanation when the destination matches an approved storage service and the timing aligns with policy.
- ✗
The host is part of a botnet performing DDoS attack
Why it's wrong here
Outbound traffic to one external IP suggests data exfiltration or command-and-control beaconing, not a botnet flooding victims; DDoS generates high inbound or spoofed outbound traffic to many targets. Botnet membership would be the suspicion when a host contacts numerous known C2 servers or participates in coordinated floods.
- ✓
Data exfiltration is occurring
Why this is correct
Large outbound transfers from one internal host to an external IP outside business hours, far exceeding baseline, match data exfiltration behaviour. NetFlow records volume and direction, not payload, so the anomaly itself signals possible data theft rather than scanning or denial of service, which produce different traffic patterns.
- ✗
The host is performing legitimate software updates
Why it's wrong here
Legitimate updates typically occur on scheduled cycles and would affect many hosts, not one internal host sending sustained high volume to a single external address overnight. Update traffic is the expected explanation when patching windows are documented and the destination matches known vendor infrastructure.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.