Courseiva

200-201 Network Intrusion Analysis Practice Question

An alert shows a high volume of outbound traffic from an internal host to an external IP using FTP. The data includes files with names matching internal document names. This activity is most likely:

⚠ Common exam trap

Many candidates confuse high-volume outbound traffic with benign activities like backups or C2, when the key indicators are the external destination and the sensitive file names, which point to exfiltration.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Data exfiltration

The scenario describes an internal host sending a high volume of outbound FTP traffic to an external IP, with file names matching internal document names. This pattern is characteristic of data exfiltration, where an attacker steals sensitive data by transferring it to an external command-and-control (C2) or staging server. FTP is commonly used because it is a standard protocol that may not be blocked, and the file names indicate the data is likely proprietary or confidential. The volume and direction (outbound) further support exfiltration rather than normal backup or scanning.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    C2 beaconing

    Why it's wrong here

    C2 beaconing produces small, regular callbacks to a controller, not bulk FTP transfers of document-named files. It is tempting because beaconing is the classic sign of external command-and-control, but it would be the right answer only for periodic, low-volume, fixed-interval connections rather than sustained exfiltration of internal data.

  • ✗

    Normal backup operation

    Why it's wrong here

    Backups normally run to internal servers or sanctioned cloud endpoints over scheduled windows, not to an arbitrary external IP via FTP. It is tempting because bulk outbound file transfer resembles backup traffic, but it would be correct only where the destination is an approved backup host and the timing matches a defined job.

  • ✗

    Port scanning

    Why it's wrong here

    Port scanning sends small probes across many ports and hosts to map services; it does not transfer document files to one external address. It is tempting because scanning is also suspicious outbound activity, but it would be correct only for reconnaissance traffic showing varied ports and connection attempts, not sustained FTP data transfer.

  • ✓

    Data exfiltration

    Why this is correct

    FTP transfers of internal document names to an external IP indicate unauthorised data movement off the network. The high outbound volume, external destination and sensitive file naming together satisfy the exfiltration pattern rather than normal FTP use or scanning.

About these practice questions

This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.