Courseiva
Network Intrusion Analysis →mediumMultiple Select

200-201 Network Intrusion Analysis Practice Question

A SOC analyst is investigating a suspected network intrusion and reviews NetFlow records. The analyst observes a sudden increase in outbound traffic from a single internal host to an external IP address, with large data volumes during off-hours. Which two additional indicators should the analyst examine to confirm data exfiltration? (Choose two.)

⚠ Common exam trap

The trap here is focusing on port-based or authentication indicators instead of the volume and directionality of data, which are the key flow characteristics for confirming exfiltration.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The duration and consistency of the outbound flow to the external IP

To confirm exfiltration from flow records, the analyst should look at the outbound-to-inbound byte ratio and the duration and consistency of the outbound flow. A high ratio and a sustained, consistent transfer to the same external IP, especially during off-hours, strongly support data exfiltration. Port counts, benign DNS queries, and failed logins are less directly related to confirming outbound data theft.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The duration and consistency of the outbound flow to the external IP

    Why this is correct

    Sustained, consistent outbound flows to the same external IP over an extended period suggest an automated transfer of data. Combined with large volumes during off-hours, this pattern supports exfiltration rather than normal user activity. Analyzing flow duration and consistency helps distinguish a deliberate data transfer from sporadic or interactive traffic.

  • ✗

    The number of distinct destination ports contacted by the internal host

    Why it's wrong here

    The number of distinct destination ports is more relevant to port scanning or service enumeration than to data exfiltration. Exfiltration typically uses a single port or a small set of ports for the transfer. While unusual port usage can be a clue, the count of destination ports alone does not confirm data leaving the network.

  • ✗

    The number of failed login attempts on the internal host

    Why it's wrong here

    Failed login attempts relate to authentication attacks such as brute-forcing, not to data exfiltration. The scenario focuses on outbound traffic volumes and off-hours transfers. While failed logins could indicate a compromised host, they do not directly confirm that data is being exfiltrated to the external IP.

  • ✓

    The ratio of outbound bytes to inbound bytes for the host

    Why this is correct

    A high outbound-to-inbound byte ratio indicates that the host is sending far more data than it receives, which is consistent with exfiltration. Normal interactive sessions are roughly balanced or inbound-heavy. Examining this ratio for the suspicious host helps confirm that large volumes of data are being uploaded to the external IP.

  • ✗

    The presence of repeated DNS queries to known benign domains

    Why it's wrong here

    Repeated DNS queries to benign domains are common in normal network activity and do not indicate exfiltration. The scenario already involves a suspicious external IP and large outbound volumes, so benign DNS lookups would not confirm the exfiltration. This indicator is too generic and unrelated to the specific data transfer.

About these practice questions

One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.