200-201 Security Monitoring Practice Question
A SOC analyst is reviewing Cisco Firepower and NetFlow records for a suspected lateral movement campaign inside the corporate network. Which TWO monitoring observations most strongly support the hypothesis that an attacker is moving laterally using SMB? (Choose two.)
⚠ Common exam trap
The trap here is selecting any internal-to-internal traffic as lateral movement, when the distinguishing factors are the fan-out pattern on port 445 and suspicious credential reuse rather than routine update or DNS traffic.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Repeated authentication attempts using a service account against multiple servers on port 445
SMB lateral movement is characterized by one host fanning out to many internal systems on port 445 and by credential reuse, such as a service account authenticating to multiple servers. These two observations together distinguish attacker pivoting from normal file share access, making them the strongest supporting evidence.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Repeated authentication attempts using a service account against multiple servers on port 445
Why this is correct
Using one service account to authenticate to many servers over SMB suggests credential reuse for lateral movement, especially if the account is not normally used interactively. Attackers commonly harvest service account credentials and spray them across hosts, so this pattern supports the SMB lateral movement hypothesis.
- ✗
An internal host sending large volumes of ICMP echo requests to the default gateway
Why it's wrong here
ICMP echo requests to a gateway are typically connectivity checks or troubleshooting traffic and do not reflect SMB lateral movement. This observation would more likely indicate a network issue or a ping sweep, and it lacks the port 445 and authentication context needed to support the SMB hypothesis.
- ✗
A single host resolving many external DNS names over port 53
Why it's wrong here
External DNS resolution does not indicate internal SMB lateral movement. While it could suggest command-and-control or DGA activity, it is unrelated to the SMB-focused hypothesis and does not show internal host-to-host access patterns on port 445.
- ✗
A workstation downloading operating system updates from an internal WSUS server over HTTP
Why it's wrong here
Patch downloads from an internal update server are routine and use HTTP, not SMB lateral movement. This activity is expected in managed environments and does not involve the host-to-host port 445 connections or credential reuse patterns that characterize lateral movement.
- ✓
Multiple internal hosts receiving TCP connections on port 445 from a single workstation in a short time window
Why this is correct
A single workstation initiating SMB connections to many internal hosts in a short window is a hallmark of lateral movement tools that enumerate and access administrative shares. Normal user behavior rarely produces this fan-out pattern, so it is a strong indicator that an attacker is pivoting across the network using SMB.
Go deeper
Related to this question
About these practice questions
One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.