Courseiva
Network Intrusion Analysis →mediumMultiple Select

200-201 Network Intrusion Analysis Practice Question

An analyst investigates a suspected data exfiltration event and captures outbound traffic from a compromised host. The traffic uses HTTPS to an unfamiliar external domain and shows consistent large uploads at regular intervals. Which two indicators would most strongly support the conclusion that this is automated exfiltration rather than normal user browsing? (Choose two.)

⚠ Common exam trap

The trap here is favoring infrastructure clues like new domains or self-signed certificates over behavioral patterns that actually reveal automation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The uploads occur at fixed intervals with near-identical byte counts

Automated exfiltration is best identified by behavior: uploads at fixed intervals with near-identical sizes indicate a scheduled tool, and outbound data with no matching user-driven inbound requests shows the transfer is not interactive browsing. Domain age, certificate issuer, and TLS version describe infrastructure or protocol choices that legitimate and malicious traffic share, so they are weaker indicators and do not specifically demonstrate automation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The connection uses TLS version 1.2

    Why it's wrong here

    TLS 1.2 is widely used by legitimate sites and attackers alike, so its presence carries no discriminating value for automation. It describes protocol version, not behavior or intent. Relying on it would produce false positives across most of the internet, and it does not help separate scheduled malware uploads from ordinary encrypted browsing in this investigation.

  • ✗

    The TLS certificate uses a self-signed issuer

    Why it's wrong here

    Self-signed certificates appear in both malicious and internal legitimate services, and many attackers now use valid certificates to blend in. Certificate issuer alone does not indicate automation or exfiltration; it only speaks to trust validation. Since the question asks about automated behavior, this indicator is less probative than the upload timing and size consistency observed in the captures.

  • ✓

    The uploads occur at fixed intervals with near-identical byte counts

    Why this is correct

    Automated exfiltration tools typically beacon or upload on a schedule with consistent payload sizes, producing regular intervals and near-identical byte counts. Human browsing is irregular in both timing and volume. This periodicity and uniformity are strong behavioral indicators that a script or malware, not a person, is generating the traffic, making it a reliable discriminator in this scenario.

  • ✗

    The destination domain was registered recently and has no reputation history

    Why it's wrong here

    A newly registered domain with no reputation is suspicious but not conclusive for automated exfiltration; many legitimate services also use new domains. Reputation alone does not distinguish automated uploads from a user visiting a new site. Without the timing and volume patterns, this indicator is weak, so it does not by itself support the automated-exfiltration conclusion as strongly as behavioral regularity.

  • ✓

    The client sends data without any corresponding inbound user-driven requests

    Why this is correct

    Automated exfiltration pushes data outbound without interactive request patterns from the user. Normal browsing involves request-response pairs driven by clicks and page loads. Observing outbound uploads with no corresponding user-initiated inbound activity strongly suggests a script or malware transferring collected data, which supports the automated exfiltration conclusion when combined with periodic upload behavior.

About these practice questions

Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.