200-201 Network Intrusion Analysis Practice Question
An analyst inspects a PCAP and finds a TCP stream where the client and server exchange data in alternating small chunks, each packet's payload is roughly 40 to 60 bytes, and the conversation lasts over two hours with consistent inter-packet delays of about ten seconds. The destination port is 443 but the payload is not TLS. Which conclusion is best supported?
⚠ Common exam trap
The trap here is treating the destination port as proof of the protocol, when the payload inspection shows no TLS and the timing profile contradicts normal web browsing.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The traffic is a reverse shell or command-and-control channel using interactive command semantics
Long-lived sessions with alternating short payloads and a steady interval are characteristic of interactive command-and-control or reverse shells, where each message carries a command or its output. Bulk transfers, TLS cipher negotiation, and DNS-over-HTTPS all produce different payload sizes, framing, and timing. The use of port 443 without TLS framing strengthens the conclusion that the port is being used to evade egress filtering rather than for legitimate web traffic.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The traffic is a large file transfer that has been fragmented by the network
Why it's wrong here
File transfers generate sustained high-volume payloads and, when fragmented, still show reassembled data totaling megabytes. Here each payload is only tens of bytes, so the aggregate data volume over two hours is trivial. Fragmentation also occurs at the IP layer and would produce fragments with offset fields, not a clean request-response cadence. The size and rhythm of the exchange rule out bulk transfer.
- ✓
The traffic is a reverse shell or command-and-control channel using interactive command semantics
Why this is correct
Alternating small payloads, long duration, and steady delays are hallmarks of an interactive remote shell or beacon where each request and response carries a short command or result. A reverse shell keeps the session alive for hours, and the ten-second cadence reflects either human interaction or a beacon interval. The non-TLS payload on port 443 confirms deliberate port masquerading to blend with expected HTTPS traffic.
- ✗
The traffic is a DNS-over-HTTPS session resolving names for a busy client
Why it's wrong here
DNS-over-HTTPS uses HTTP/2 or HTTP/3 framing inside TLS and produces request-response pairs tied to actual name lookups. The payload here is not TLS, and the ten-second interval does not match resolver caching behavior for a busy client, which would be bursty. DNS-over-HTTPS also would not run continuously for two hours with fixed-size tiny messages, so this does not fit the observed pattern.
- ✗
The traffic is a misconfigured TLS session negotiating an unusually small cipher block
Why it's wrong here
TLS handshakes begin with a recognizable ClientHello and ServerHello containing version and cipher suite fields, and the record layer has a defined structure. The analyst confirmed the payload is not TLS, so no cipher negotiation occurred. Cipher block size also does not shrink application payloads to tens of bytes on a fixed ten-second schedule. The absence of TLS framing invalidates the cipher-misconfiguration theory.
Go deeper
Related to this question
About these practice questions
One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.