Courseiva
Network Intrusion Analysis →mediumMultiple Choice

200-201 Network Intrusion Analysis Practice Question

A SOC analyst monitors outbound traffic from a corporate network and notices a single internal host contacting an external server on TCP port 53, but the payloads contain fixed-length, non-DNS binary data with no query/response structure. The host also makes outbound connections to the same external IP on TCP port 4444. Which technique is the attacker most likely using?

⚠ Common exam trap

The trap here is assuming any traffic on port 53 is DNS; the port number alone does not define the protocol, and payload structure must be inspected.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Command-and-control over a non-standard port masquerading as DNS

Traffic to TCP port 53 that does not follow DNS message formatting, combined with a second connection to TCP port 4444, indicates a custom command-and-control channel deliberately placed on a commonly permitted port. Attackers choose such ports to slip past egress filters that allow DNS. DNS tunneling and DoH would preserve DNS semantics or use TLS on 443, and SMTP abuse would use mail ports and commands, none of which match the observed binary, non-DNS payloads.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    DNS over HTTPS (DoH) tunneling

    Why it's wrong here

    DoH encapsulates DNS queries inside HTTPS on TCP port 443, not TCP port 53. Here the traffic uses TCP port 53 with non-DNS binary payloads, which is inconsistent with DoH. DoH would also show TLS handshakes and certificate exchanges to a DoH resolver, and the client would not simultaneously open a raw TCP/4444 channel to the same server. This option misidentifies the protocol and port behavior observed.

  • ✗

    SMTP relay abuse for data exfiltration

    Why it's wrong here

    SMTP abuse would involve TCP port 25 or 587 and mail protocol commands such as HELO, MAIL FROM, and RCPT TO. The observed traffic is on TCP port 53 and 4444 with binary payloads, which does not match SMTP. There is also no mail server interaction or message envelope, so this option does not fit the evidence and mischaracterizes the protocol in use.

  • ✓

    Command-and-control over a non-standard port masquerading as DNS

    Why this is correct

    Using TCP port 53 with non-DNS binary payloads while also connecting to TCP port 4444 is a classic masquerading technique: the attacker picks a port commonly allowed through firewalls and tunnels a custom C2 protocol over it. The absence of DNS query/response formatting and the paired 4444 connection confirm a custom C2 channel, not legitimate DNS. This matches real-world malware that abuses trusted ports to evade egress filtering.

  • ✗

    DNS tunneling over TCP port 53

    Why it's wrong here

    DNS tunneling typically uses TXT, NULL, or CNAME records with encoded subdomains, and the payloads preserve DNS query/response semantics. Here the analyst sees fixed-length non-DNS binary data with no query structure, so it is not DNS tunneling. The simultaneous TCP/4444 connection also points to a raw command-and-control channel, not DNS-based exfiltration or control.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.