Courseiva

200-201 Network Intrusion Analysis Practice Question

An analyst examining a PCAP sees a host send an HTTP GET request where the User-Agent string contains a long, random-looking hexadecimal value, the request path includes a similarly random string, and the server responds with a 404 status code but a response body of several kilobytes. This pattern repeats every 60 seconds. Which activity is most likely occurring?

⚠ Common exam trap

The trap here is dismissing the traffic because of the 404 status, when attackers deliberately return error codes while smuggling data in the response body.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Command-and-control beaconing over HTTP with data hidden in request and response fields

The fixed 60-second cadence, random hex identifiers in both the User-Agent and URI, and a substantial response body paired with a 404 status together indicate HTTP-based command-and-control. Implants poll at set intervals for tasking, encode session identifiers to evade signatures, and hide instructions in what appears to be an error response. Normal CDN traffic, vulnerability scanning, and backoff retries all produce different timing, field content, and response characteristics.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Command-and-control beaconing over HTTP with data hidden in request and response fields

    Why this is correct

    A fixed 60-second interval, random-looking identifiers in the User-Agent and URI, and a large response body despite a 404 status are classic HTTP beaconing with covert channel encoding. Legitimate clients do not send random hex in these fields, and a true 404 would not carry kilobytes of meaningful content. The implant is polling for instructions and receiving tasking data disguised as an error page.

  • ✗

    A content delivery network serving cached assets to a browser with a corrupted user agent

    Why it's wrong here

    CDNs return 200-series responses with cache headers and real asset bodies, and browser user agents are stable strings, not per-request random hex. A corrupted user agent would not also produce a matching random URI on a strict one-minute schedule. The combination of fields and timing points away from normal content delivery and toward deliberate obfuscation of a command channel.

  • ✗

    A misconfigured application retrying a failed API call with exponential backoff

    Why it's wrong here

    Exponential backoff increases the delay between retries rather than holding a constant 60-second interval, and retries reuse the same request path instead of generating fresh random identifiers each time. A failing API call would also not receive kilobytes of body content in a 404 response. The regularity and the encoded fields contradict the backoff-retry explanation.

  • ✗

    An automated vulnerability scanner fuzzing the web application

    Why it's wrong here

    Vulnerability scanners generate high request rates with varied payloads aimed at many endpoints, not a single repeating request every 60 seconds. They also typically use recognizable user agents or none at all, and they do not treat a 404 as a successful result while continuing the same cadence. The fixed interval and encoded fields indicate persistence, which scanners do not exhibit.

About these practice questions

Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.