200-201 Security Monitoring Practice Question
A SOC analyst is reviewing NetFlow records exported from a border router and notices a single internal host initiating outbound connections to more than 300 distinct external IP addresses on TCP port 443 within a five-minute window, with each flow carrying only a few hundred bytes. Which security monitoring conclusion is best supported by this evidence?
⚠ Common exam trap
The trap here is assuming that any burst of outbound HTTPS traffic is command-and-control beaconing, when the distinguishing factor is the number of distinct destinations and the near-constant small flow size, not the port used.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The host is likely performing a port scan or host sweep against external targets.
NetFlow captures metadata rather than payloads, but the metadata here is decisive: one internal host opening connections to hundreds of distinct external addresses on the same port with uniformly tiny byte counts is a host sweep. Beaconing would target few destinations; exfiltration would move large volumes to one destination; amplification would be inbound UDP. The fan-out pattern uniquely supports scanning activity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The host is likely exfiltrating a large database to a single external cloud storage provider.
Why it's wrong here
Data exfiltration produces flows with large outbound byte counts concentrated toward one or a few destinations. This scenario shows the opposite: many destinations and very small per-flow volume. Treating this as exfiltration would waste containment effort on the wrong threat model and overlook the scanning behavior that the flow record actually demonstrates.
- ✗
The host is likely the victim of a reflected DNS amplification attack.
Why it's wrong here
A reflected amplification attack would show large inbound UDP responses from many sources toward the victim, typically on port 53, not outbound TCP 443 flows initiated by the internal host. The direction, transport, and port in the NetFlow records do not match that attack pattern, so this conclusion is unsupported by the evidence presented.
- ✓
The host is likely performing a port scan or host sweep against external targets.
Why this is correct
Hundreds of distinct destination addresses contacted in a very short window, each with minimal data transferred, is the classic NetFlow signature of a host sweep. Because the flows target port 443, the sweep is aimed at discovering reachable HTTPS services. NetFlow's IP, port, and byte-count fields are sufficient to identify this fan-out behavior without full packet capture.
- ✗
The host is likely performing beaconing to a command-and-control server over HTTPS.
Why it's wrong here
Beaconing produces repeated connections to a small, stable set of destinations at regular intervals, not 300 distinct external addresses in five minutes. The fan-out pattern and tiny byte counts here point to a scanning or distribution mechanism. Flagging this as beaconing would misdirect the investigation toward C2 infrastructure hunting instead of identifying the scanning host itself.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.