200-201 Security Monitoring Practice Question
A Zeek connection log shows a high number of connections from a single internal IP to many different external IPs on port 25, with small payload sizes. Which behavior is most likely indicated?
⚠ Common exam trap
Cisco often tests the association of well-known ports with their protocols, and the trap here is that candidates may confuse port 25 with other common ports like 53 (DNS) or 21 (FTP), leading them to select DNS tunneling or FTP exfiltration instead of recognizing the SMTP spam pattern.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Spam email campaign or SMTP scanning
Port 25 is the default SMTP port used for email transmission. A high volume of connections from a single internal IP to many different external IPs on port 25, with small payload sizes, is characteristic of a spam email campaign or SMTP scanning. This pattern suggests the host is either sending bulk spam emails or probing external mail servers for open relay or user enumeration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
DNS tunneling
Why it's wrong here
DNS uses port 53, not 25.
- ✗
Secure web browsing
Why it's wrong here
Secure web browsing uses TCP 443, with larger, longer-lived sessions to a small set of destinations. Port 25 with many external IPs and small payloads indicates SMTP abuse such as spam relay or botnet mail. Web browsing is tempting because it is common outbound traffic, but the port rules it out.
- ✗
Data exfiltration using FTP
Why it's wrong here
FTP exfiltration uses ports 20 and 21 and typically transfers larger payloads to one destination. Port 25 with many external recipients and small payloads matches SMTP-based spam or malware distribution. FTP is tempting because both involve outbound data transfer, but the port and traffic pattern contradict it.
- ✓
Spam email campaign or SMTP scanning
Why this is correct
Many outbound connections to diverse external hosts on port 25, with tiny payloads, indicate SMTP scanning or spam relay activity. A legitimate mail server contacts few destinations with larger message bodies; this fan-out pattern from one internal host satisfies the stem's high-connection, small-payload constraint.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.