Courseiva
Network Intrusion Analysis →mediumMultiple Choice

200-201 Network Intrusion Analysis Practice Question

A SOC analyst is investigating a suspected data exfiltration event on a corporate network. The analyst runs a Wireshark display filter on a captured PCAP and sees a large volume of outbound packets from an internal workstation to an external IP address, all with the same destination port and with the TCP PSH flag set on nearly every packet. The payloads are small but consistently sized, and the transfer continues for over 30 minutes. Which statement best explains why this traffic pattern is suspicious in the context of network intrusion analysis?

⚠ Common exam trap

The trap here is assuming that a TCP flag like PSH is inherently malicious or that a single destination port implies encryption, when the real signal is the sustained, automated transfer pattern.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The steady, long-duration outbound flow with consistent packet sizes suggests a scripted or automated transfer, which is consistent with data exfiltration rather than normal interactive user activity.

The correct answer focuses on behavioral indicators: a long, steady, automated-looking outbound flow with uniform packet sizes and the PSH flag set on most packets. This pattern is typical of data exfiltration tools that chunk and push data continuously, unlike bursty interactive user traffic. The other options misattribute meaning to TCP flags or make incorrect claims about detection limits, which would mislead an analyst.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The PSH flag indicates the sender is bypassing TCP flow control, which is a known evasion technique used by rootkits to hide data in the TCP header.

    Why it's wrong here

    The PSH flag does not bypass TCP flow control; it simply tells the receiver to push buffered data to the application immediately. Attackers do not use PSH to hide data in the TCP header—header fields like sequence numbers or urgent pointers are more relevant for covert channels. This option mischaracterizes a normal TCP mechanism as an evasion technique, which is not supported by the scenario.

  • ✗

    The presence of the PSH flag on nearly every packet means the connection is using TCP Fast Open, which is only seen in malicious command-and-control channels.

    Why it's wrong here

    TCP Fast Open is an option negotiated at connection setup using a cookie, not a behavior indicated by the PSH flag. The PSH flag is standard in many applications that send small messages. Asserting that PSH indicates TCP Fast Open is technically wrong, and TCP Fast Open is not exclusive to malicious C2 channels; it can be used by legitimate web services.

  • ✗

    The use of a single destination port for all outbound packets indicates the traffic is encrypted, and encrypted exfiltration cannot be detected by network analysis.

    Why it's wrong here

    A single destination port does not imply encryption; many protocols use one port, and encryption can occur on various ports. Moreover, encrypted exfiltration can still be detected through metadata analysis, volume anomalies, and timing patterns. Claiming encrypted exfiltration is undetectable is incorrect and would lead an analyst to prematurely dismiss a valid lead.

  • ✓

    The steady, long-duration outbound flow with consistent packet sizes suggests a scripted or automated transfer, which is consistent with data exfiltration rather than normal interactive user activity.

    Why this is correct

    A sustained, uniform outbound flow over 30 minutes with uniform packet sizes and PSH on nearly every packet strongly suggests an automated tool pushing data out, not a human browsing or emailing. Exfiltration tools often chunk data into consistent sizes to optimize throughput. In intrusion analysis, this beaconing-like regularity is a key indicator of malicious data transfer rather than legitimate user traffic.

About these practice questions

This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.