Courseiva
Security Monitoring →hardMultiple Choice

200-201 Security Monitoring Practice Question

A Zeek connection log shows a high number of connections from a single internal IP to many different external IPs on port 25, with small payload sizes. Which behavior is most likely indicated?

⚠ Common exam trap

Cisco often tests the association of well-known ports with their protocols, and the trap here is that candidates may confuse port 25 with other common ports like 53 (DNS) or 21 (FTP), leading them to select DNS tunneling or FTP exfiltration instead of recognizing the SMTP spam pattern.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Spam email campaign or SMTP scanning

Port 25 is the default SMTP port used for email transmission. A high volume of connections from a single internal IP to many different external IPs on port 25, with small payload sizes, is characteristic of a spam email campaign or SMTP scanning. This pattern suggests the host is either sending bulk spam emails or probing external mail servers for open relay or user enumeration.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    DNS tunneling

    Why it's wrong here

    DNS uses port 53, not 25.

  • ✗

    Secure web browsing

    Why it's wrong here

    Secure web browsing uses TCP 443, with larger, longer-lived sessions to a small set of destinations. Port 25 with many external IPs and small payloads indicates SMTP abuse such as spam relay or botnet mail. Web browsing is tempting because it is common outbound traffic, but the port rules it out.

  • ✗

    Data exfiltration using FTP

    Why it's wrong here

    FTP exfiltration uses ports 20 and 21 and typically transfers larger payloads to one destination. Port 25 with many external recipients and small payloads matches SMTP-based spam or malware distribution. FTP is tempting because both involve outbound data transfer, but the port and traffic pattern contradict it.

  • ✓

    Spam email campaign or SMTP scanning

    Why this is correct

    Many outbound connections to diverse external hosts on port 25, with tiny payloads, indicate SMTP scanning or spam relay activity. A legitimate mail server contacts few destinations with larger message bodies; this fan-out pattern from one internal host satisfies the stem's high-connection, small-payload constraint.

About these practice questions

Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.