200-201 Network Intrusion Analysis Practice Question
A SOC analyst is investigating a suspected network intrusion and reviews NetFlow records. The analyst observes a sudden increase in outbound traffic from a single internal host to an external IP address, with large data volumes during off-hours. Which two additional indicators should the analyst examine to confirm data exfiltration? (Choose two.)
⚠ Common exam trap
The trap here is focusing on port-based or authentication indicators instead of the volume and directionality of data, which are the key flow characteristics for confirming exfiltration.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The duration and consistency of the outbound flow to the external IP
To confirm exfiltration from flow records, the analyst should look at the outbound-to-inbound byte ratio and the duration and consistency of the outbound flow. A high ratio and a sustained, consistent transfer to the same external IP, especially during off-hours, strongly support data exfiltration. Port counts, benign DNS queries, and failed logins are less directly related to confirming outbound data theft.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The duration and consistency of the outbound flow to the external IP
Why this is correct
Sustained, consistent outbound flows to the same external IP over an extended period suggest an automated transfer of data. Combined with large volumes during off-hours, this pattern supports exfiltration rather than normal user activity. Analyzing flow duration and consistency helps distinguish a deliberate data transfer from sporadic or interactive traffic.
- ✗
The number of distinct destination ports contacted by the internal host
Why it's wrong here
The number of distinct destination ports is more relevant to port scanning or service enumeration than to data exfiltration. Exfiltration typically uses a single port or a small set of ports for the transfer. While unusual port usage can be a clue, the count of destination ports alone does not confirm data leaving the network.
- ✗
The number of failed login attempts on the internal host
Why it's wrong here
Failed login attempts relate to authentication attacks such as brute-forcing, not to data exfiltration. The scenario focuses on outbound traffic volumes and off-hours transfers. While failed logins could indicate a compromised host, they do not directly confirm that data is being exfiltrated to the external IP.
- ✓
The ratio of outbound bytes to inbound bytes for the host
Why this is correct
A high outbound-to-inbound byte ratio indicates that the host is sending far more data than it receives, which is consistent with exfiltration. Normal interactive sessions are roughly balanced or inbound-heavy. Examining this ratio for the suspicious host helps confirm that large volumes of data are being uploaded to the external IP.
- ✗
The presence of repeated DNS queries to known benign domains
Why it's wrong here
Repeated DNS queries to benign domains are common in normal network activity and do not indicate exfiltration. The scenario already involves a suspicious external IP and large outbound volumes, so benign DNS lookups would not confirm the exfiltration. This indicator is too generic and unrelated to the specific data transfer.
Go deeper
Related to this question
About these practice questions
One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.