200-201 Security Monitoring Practice Question
A SOC analyst notices that a workstation is generating NetFlow records showing repeated outbound connections to 203.0.113.45 on port 443 at regular 60-second intervals, with each flow transferring approximately 4 KB. The destination IP has no reputation data. Which analysis approach would best determine whether this traffic represents C2 beaconing?
⚠ Common exam trap
The trap here is assuming that blocking the destination IP is the best immediate action, when doing so prematurely can destroy evidence and prevent full identification of the compromised host and C2 channel.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Correlate the flow timestamps with DNS query logs and endpoint process telemetry to identify the initiating process and any associated domain resolutions.
The regular 60-second interval and small, consistent transfers are classic beaconing indicators. NetFlow shows the pattern but not the cause. Correlating flow timestamps with DNS logs and endpoint process telemetry identifies the initiating process and any resolved domains, providing definitive evidence of C2 and enabling proper containment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Block all outbound traffic to 203.0.113.45 at the perimeter firewall and monitor for any user complaints about lost connectivity.
Why it's wrong here
Blocking the IP immediately may stop the beacon but destroys the opportunity to confirm C2 and identify the infected host's full behavior. User complaints are not a reliable detection method, and the analyst would lose valuable forensic evidence needed to scope the incident.
- ✓
Correlate the flow timestamps with DNS query logs and endpoint process telemetry to identify the initiating process and any associated domain resolutions.
Why this is correct
NetFlow alone shows only metadata; correlating timestamps with DNS logs and endpoint telemetry reveals the process responsible and whether it resolves a suspicious domain. This combination is the most reliable way to confirm beaconing behavior and identify the malware family or C2 infrastructure.
- ✗
Run a full antivirus scan on the workstation and review the scan results for any detected malware signatures.
Why it's wrong here
Antivirus scans rely on known signatures and often miss custom or fileless C2 implants. The regular interval and small transfer size strongly suggest beaconing, which may not produce a file-based detection; thus, an AV scan alone is insufficient to confirm or rule out C2 activity.
- ✗
Increase the NetFlow sampling rate on the router to capture every packet and then analyze the payload contents for malicious strings.
Why it's wrong here
NetFlow does not capture payload contents; it only records flow metadata. Increasing the sampling rate improves metadata granularity but still cannot reveal payload strings, so this approach would not confirm C2 beaconing or identify the malicious process.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.