200-201 Security Monitoring Practice Question
A SOC analyst is reviewing network telemetry from Cisco Stealthwatch and notices a host inside the corporate network initiating repeated outbound connections to a single external IP address. Each connection is short-lived (less than 5 seconds) and occurs at irregular intervals, with varying destination ports. The analyst suspects command-and-control activity. Which approach would best confirm this suspicion using available telemetry?
⚠ Common exam trap
The trap here is assuming that full packet capture is always necessary, when flow and DNS correlation often provide faster and sufficient confirmation of C2 activity.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Correlate NetFlow records with DNS logs to identify the domain associated with the external IP and check its reputation.
The correct approach is to correlate NetFlow data with DNS logs. NetFlow reveals the external IP and connection patterns, while DNS logs can link that IP to a domain. Checking the domain's reputation against threat intelligence confirms whether it is associated with known C2 infrastructure. This method leverages existing telemetry efficiently and is a standard practice in security monitoring.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Correlate NetFlow records with DNS logs to identify the domain associated with the external IP and check its reputation.
Why this is correct
Correlating NetFlow records with DNS logs links the external IP to a domain, which can then be checked against threat intelligence. This confirms whether the destination is a known C2 server. Short-lived connections with varying ports are typical of beaconing, and identifying the domain helps validate the suspicion, making this the most effective approach.
- ✗
Review firewall logs to see if any inbound connections from the external IP were blocked.
Why it's wrong here
Firewall logs show inbound connection attempts, but the scenario describes outbound connections from an internal host. Inbound blocks would not confirm C2 activity, as C2 is typically outbound. This approach focuses on the wrong direction and would not provide evidence of the suspected beaconing, making it ineffective for confirmation.
- ✗
Capture full packet data for the host and inspect the payload for known malware signatures.
Why it's wrong here
Full packet capture may be impractical for continuous monitoring and could miss encrypted C2 traffic. While payload inspection can detect known signatures, modern C2 often uses encryption or obfuscation, making signature-based detection unreliable. This approach is also resource-intensive and may not scale, so it is not the best first step for confirming beaconing behavior.
- ✗
Check the host's ARP cache for entries mapping the external IP to a MAC address.
Why it's wrong here
ARP operates at Layer 2 and is used for local subnet resolution; it does not map external IP addresses to MAC addresses. The external IP would be reached via a router, so ARP cache entries would not contain it. This approach is technically invalid for the scenario and would not yield useful information about the external connections.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.