Courseiva
Security Monitoring →hardMultiple Choice

200-201 Security Monitoring Practice Question

A threat hunter reviews Cisco Stealthwatch flow data and sees an internal server sending periodic 300-byte outbound flows to an external IP every 60 seconds, with consistent packet sizes and no matching inbound response beyond TCP acknowledgments. The server's DNS queries for that IP resolve through a newly registered domain. Which monitoring approach best characterizes this activity as beaconing rather than normal application traffic?

⚠ Common exam trap

The trap here is focusing on the low byte count and concluding the traffic is too small to matter instead of examining its timing regularity.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Analyze flow periodicity and packet-size consistency over time

Beaconing is a behavioral pattern characterized by regular connection intervals and consistent payload sizes, often with minimal server response. Flow telemetry preserves the timing and byte counts needed to detect that cadence, so periodicity and size consistency analysis is the right approach. Volume ranking, blocklist matching, and patch verification do not evaluate the temporal pattern that separates automated C2 from normal traffic.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Compare the flow's byte count against the organization's top-talkers report

    Why it's wrong here

    Top-talkers reports rank hosts by volume, so a 300-byte flow every minute will never appear near the top and will be dismissed. This activity is defined by regularity and low volume, not bandwidth consumption. Using volume ranking as the discriminator would classify the beacon as insignificant, missing the very characteristic that makes beaconing detectable in flow telemetry.

  • ✗

    Check whether the destination IP appears on a threat intelligence blocklist

    Why it's wrong here

    Blocklist matching is a useful enrichment step, but newly registered C2 domains frequently evade reputation feeds for days, so a negative lookup does not rule out beaconing. The question asks how to characterize the pattern as beaconing, which requires behavioral analysis of timing and size. Relying solely on blocklists would miss the regular low-volume cadence that defines this activity.

  • ✓

    Analyze flow periodicity and packet-size consistency over time

    Why this is correct

    Beaconing is identified by repeated connections at regular intervals with near-constant payload sizes, which distinguishes it from bursty or variable user-driven traffic. Stealthwatch's flow records preserve timestamps and byte counts, so plotting inter-arrival times and sizes exposes the 60-second cadence. Correlating that pattern with the newly registered domain strengthens the characterization of automated C2 beaconing rather than normal application behavior.

  • ✗

    Verify that the server's operating system is fully patched and current

    Why it's wrong here

    Patch status is relevant to vulnerability management, not to identifying beaconing behavior in flow data. A fully patched server can still be compromised through stolen credentials or a zero-day, and an unpatched server is not automatically beaconing. This check does not analyze the periodic outbound flows, so it cannot distinguish automated C2 from legitimate scheduled application traffic.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.