Courseiva
Security Monitoring →hardMultiple Select

200-201 Security Monitoring Practice Question

A SOC analyst is reviewing proxy logs and wants to identify indicators of potential data exfiltration over HTTP. Which two patterns should the analyst treat as suspicious? (Choose two.)

⚠ Common exam trap

The trap here is focusing on inbound downloads or benign errors, when exfiltration is characterized by outbound uploads to suspicious destinations.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Large outbound POST requests to a single external IP address at regular intervals.

Exfiltration over HTTP often appears as large outbound uploads, especially to new or untrusted destinations. Regular large POST requests and high-volume uploads to newly registered domains both indicate data leaving the environment in a manner inconsistent with normal business traffic. These patterns warrant deeper investigation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Large outbound POST requests to a single external IP address at regular intervals.

    Why this is correct

    Large outbound POST requests at regular intervals suggest automated data transfer to an external host. Legitimate user browsing rarely produces consistent, large uploads on a schedule. This pattern is consistent with exfiltration tools that beacon or upload data in chunks, making it a suspicious indicator worth investigating.

  • ✓

    Outbound connections to a newly registered domain with a high volume of data uploaded.

    Why this is correct

    A newly registered domain receiving a high volume of uploaded data is a strong exfiltration indicator. Attackers often use recently created domains to avoid reputation-based blocking. Combining new domain age with large uploads points to potential data theft rather than normal business traffic.

  • ✗

    HTTP 404 errors generated by users mistyping URLs in the browser.

    Why it's wrong here

    HTTP 404 errors from mistyped URLs are common user errors and do not indicate data leaving the network. They involve small requests and no uploads. While they can clutter logs, they are not a suspicious pattern for exfiltration and should not be treated as such.

  • ✗

    Repeated GET requests to the same internal web server for static images.

    Why it's wrong here

    Repeated GET requests for static images on an internal server are typical of normal web browsing or application behavior. They do not involve external destinations or large uploads, so they are not indicative of data exfiltration. This pattern is benign and should not be prioritized as suspicious.

  • ✗

    Downloading software updates from a known vendor's HTTPS site.

    Why it's wrong here

    Downloading updates from a known vendor over HTTPS is normal, expected traffic. It is inbound rather than outbound data, and the destination has a trusted reputation. This activity does not match exfiltration patterns, which involve outbound data transfer to untrusted or new destinations.

About these practice questions

This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.