Courseiva
Network Intrusion Analysis →mediumMultiple Choice

200-201 Network Intrusion Analysis Practice Question

A SOC analyst is reviewing NetFlow records and notices that a single internal host has initiated connections to 1,024 distinct destination IP addresses on TCP port 445 within a five-minute window. Each connection attempt lasts under one second and transfers fewer than three packets. Which activity does this pattern most strongly indicate?

⚠ Common exam trap

The trap here is assuming any burst of SMB traffic is normal file-sharing activity, when the decisive clue is the count of distinct destination hosts rather than the protocol itself.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

SMB worm propagation scanning the local subnet and adjacent ranges

Rapid connections from one internal host to a large number of unique destinations on a single service port, each lasting only a moment and exchanging minimal data, is the signature of automated SMB scanning used for worm propagation. Legitimate SMB workloads target a small, stable set of servers and move meaningful data. NetFlow aggregation does not create destination diversity, and name resolution uses different ports and protocols, so the fan-out reflects real scanning behavior.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    SMB worm propagation scanning the local subnet and adjacent ranges

    Why this is correct

    The short-lived, low-packet-count connections to many hosts on TCP 445 in a compressed timeframe match worm-style SMB scanning, where malware enumerates targets looking for writable shares or vulnerable services before moving laterally. A benign file server or backup job would not touch over a thousand distinct hosts in five minutes, and the uniform port reinforces automated propagation rather than user-driven access.

  • ✗

    An SMB client resolving a hostname through repeated broadcast name queries

    Why it's wrong here

    Name resolution failures use UDP port 137 or DNS, not TCP 445. Even when a client retries a name lookup, it targets broadcast or configured name servers, not a thousand routable destination addresses. The destination port and the connection-oriented nature of the observed traffic point to service enumeration rather than name resolution, so this explanation does not fit the evidence.

  • ✗

    A legitimate backup application performing parallel SMB writes to storage nodes

    Why it's wrong here

    Backup software does open many SMB sessions, but it connects to a known, small set of storage targets and sustains longer sessions with substantial data transfer. Here the fan-out is to 1,024 distinct addresses with fewer than three packets each, which is inconsistent with completed SMB writes. Backup traffic would also appear at scheduled windows, not a burst of failed short connections.

  • ✗

    A normal NetFlow sampling artifact caused by flow timeout settings

    Why it's wrong here

    Flow timeout settings affect how long a single conversation is recorded, not how many distinct destination IPs a host contacts. Sampling can undercount packets, but it cannot manufacture connections to a thousand unique addresses on the same port. The breadth of destinations is real host behavior observed by the exporter, so attributing it to timeout configuration misreads how NetFlow aggregation works.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.