200-201 Network Intrusion Analysis Practice Question
A SOC analyst reviewing a packet capture notices that a single internal host has initiated hundreds of short-lived TCP sessions to the same external web server over the past hour, and every session completed a full three-way handshake before being torn down with FIN/ACK. No single session transferred more than a few kilobytes. Which traffic characteristic should the analyst use to classify this activity?
⚠ Common exam trap
The trap here is assuming that high connection volume to one destination automatically means a denial-of-service flood, when the state of the handshake and teardown reveals the true nature of the traffic.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Possible beaconing or automated application behavior, because repeated uniform short sessions at regular volume suggest periodic callbacks.
Repeated short TCP sessions with complete handshakes and consistent small payloads point to periodic automated communication such as malware beaconing, not resource-exhaustion attacks or scanning. A SYN flood and slowloris both leave connections incomplete by design, while a port scan varies destination ports and usually never completes a session. The distinguishing evidence is the uniform, repeating, fully established flow pattern.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Possible beaconing or automated application behavior, because repeated uniform short sessions at regular volume suggest periodic callbacks.
Why this is correct
Repeated, uniform, short-lived completed TCP sessions to the same external endpoint are characteristic of beaconing malware or an automated client polling a service on a timer. The consistent small transfer size and full handshake/teardown pattern distinguish it from scanning or flooding. The analyst should baseline the interval and correlate with process and destination reputation to confirm whether it is malicious command-and-control.
- ✗
A TCP SYN flood, because many connection attempts were made to one destination in a short period.
Why it's wrong here
A SYN flood leaves half-open connections because the attacker never completes the handshake, and it targets the victim's listen backlog to exhaust resources. Here every session completed the three-way handshake and was gracefully closed with FIN/ACK, so no half-open state existed. The volume alone does not make it a flood; the analyst would need to see unanswered SYNs and retransmissions instead.
- ✗
A slowloris-style denial of service, because each session stayed open for a short time.
Why it's wrong here
Slowloris holds many connections open indefinitely by sending partial HTTP requests, keeping server threads occupied. These sessions were short-lived and terminated normally, which is the opposite of the long-held, never-completing requests slowloris relies on. There is also no indication the target was a web server running out of connection slots, only that many brief sessions occurred.
- ✗
A port scan, because the host contacted the same server repeatedly.
Why it's wrong here
A port scan probes many destination ports on one or more hosts to discover listening services, typically producing RST responses for closed ports or a sweep of SYN packets without completing sessions. Here the host repeatedly reached the same service and completed full handshakes with data exchange, which is not how scanning enumerates services. The destination port was not varied across the sessions.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.