Courseiva
Security Monitoring →mediumMultiple Choice

200-201 Security Monitoring Practice Question

A SOC analyst is reviewing NetFlow records exported from the border router. A single internal workstation is generating a steady stream of outbound sessions to dozens of unique external IP addresses on TCP port 443, each lasting only a few seconds, every day at 02:00. No corresponding firewall denies are logged. Which security monitoring conclusion is most appropriate?

⚠ Common exam trap

The trap here is assuming that traffic on TCP 443 is automatically benign because it is encrypted web traffic, when the destination diversity and timing are what actually matter.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The workstation is most likely beaconing to a command-and-control infrastructure and should be escalated for endpoint triage.

Periodic outbound sessions to many distinct external hosts on a single port, occurring at a fixed hour, match the behavioural profile of malware beaconing rather than normal user or update traffic. NetFlow alone cannot confirm payload, so the analyst should pivot to DNS and endpoint data, but the pattern itself justifies escalation as a suspected command-and-control channel.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The router is misconfigured and is exporting duplicate flow records, which inflates the session count.

    Why it's wrong here

    Duplicate export would produce repeated records for the same five-tuple and timestamps, not sessions to many distinct destination addresses. The scenario describes unique external peers, so de-duplication of the collector database would not explain the pattern. Concluding a router fault ignores the more security-relevant possibility that the host itself is initiating the traffic.

  • ✓

    The workstation is most likely beaconing to a command-and-control infrastructure and should be escalated for endpoint triage.

    Why this is correct

    Periodic, low-volume fan-out to many distinct external hosts on a single common port is a classic beaconing signature, especially outside business hours. Because NetFlow records only metadata, the analyst cannot see payload, so the correct next step is to correlate the flows with endpoint telemetry and DNS logs before concluding compromise, but escalation is warranted.

  • ✗

    This is expected behaviour for a patched workstation receiving software updates from a content delivery network.

    Why it's wrong here

    A CDN update pattern usually resolves to a small, stable set of provider prefixes and recurs on a schedule tied to the update client, not to dozens of unrelated destinations every night. The breadth of unique peers and the short, uniform session duration are atypical for legitimate patch traffic, so accepting it as benign would close the investigation prematurely.

  • ✗

    The traffic is a port scan launched from the internet against the workstation and should be blocked inbound.

    Why it's wrong here

    The flows are described as outbound sessions originating from the internal workstation, so this is not an inbound scan. NetFlow direction and the absence of firewall denies also argue against externally initiated probes. Treating it as an inbound scan would misdirect the response away from the compromised endpoint and toward perimeter filtering.

About these practice questions

This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.