200-201 Network Intrusion Analysis Practice Question
A SOC analyst monitors outbound traffic from a corporate network and notices a single internal host contacting an external server on TCP port 53, but the payloads contain fixed-length, non-DNS binary data with no query/response structure. The host also makes outbound connections to the same external IP on TCP port 4444. Which technique is the attacker most likely using?
⚠ Common exam trap
The trap here is assuming any traffic on port 53 is DNS; the port number alone does not define the protocol, and payload structure must be inspected.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Command-and-control over a non-standard port masquerading as DNS
Traffic to TCP port 53 that does not follow DNS message formatting, combined with a second connection to TCP port 4444, indicates a custom command-and-control channel deliberately placed on a commonly permitted port. Attackers choose such ports to slip past egress filters that allow DNS. DNS tunneling and DoH would preserve DNS semantics or use TLS on 443, and SMTP abuse would use mail ports and commands, none of which match the observed binary, non-DNS payloads.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
DNS over HTTPS (DoH) tunneling
Why it's wrong here
DoH encapsulates DNS queries inside HTTPS on TCP port 443, not TCP port 53. Here the traffic uses TCP port 53 with non-DNS binary payloads, which is inconsistent with DoH. DoH would also show TLS handshakes and certificate exchanges to a DoH resolver, and the client would not simultaneously open a raw TCP/4444 channel to the same server. This option misidentifies the protocol and port behavior observed.
- ✗
SMTP relay abuse for data exfiltration
Why it's wrong here
SMTP abuse would involve TCP port 25 or 587 and mail protocol commands such as HELO, MAIL FROM, and RCPT TO. The observed traffic is on TCP port 53 and 4444 with binary payloads, which does not match SMTP. There is also no mail server interaction or message envelope, so this option does not fit the evidence and mischaracterizes the protocol in use.
- ✓
Command-and-control over a non-standard port masquerading as DNS
Why this is correct
Using TCP port 53 with non-DNS binary payloads while also connecting to TCP port 4444 is a classic masquerading technique: the attacker picks a port commonly allowed through firewalls and tunnels a custom C2 protocol over it. The absence of DNS query/response formatting and the paired 4444 connection confirm a custom C2 channel, not legitimate DNS. This matches real-world malware that abuses trusted ports to evade egress filtering.
- ✗
DNS tunneling over TCP port 53
Why it's wrong here
DNS tunneling typically uses TXT, NULL, or CNAME records with encoded subdomains, and the payloads preserve DNS query/response semantics. Here the analyst sees fixed-length non-DNS binary data with no query structure, so it is not DNS tunneling. The simultaneous TCP/4444 connection also points to a raw command-and-control channel, not DNS-based exfiltration or control.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.