hardMultiple ChoiceObjective-mapped
200-201 Practice Question: An analyst is investigating a host that is…
An analyst is investigating a host that is beaconing to a known malicious domain every 60 seconds. The host also shows outbound connections to multiple IPs on port 443. To confirm the beaconing, which data source is most useful?
⚠ Common exam trap
Cisco often tests the distinction between DNS logs (which show name resolution) and NetFlow (which shows actual traffic flows), leading candidates to mistakenly choose DNS logs because they associate beaconing with domain names, not realizing that the beaconing is confirmed by the connection pattern itself.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
NetFlow records from the border router.
NetFlow records from the border router provide aggregated metadata (source/destination IP, port, protocol, timestamps) that can reveal the periodic 60-second beaconing pattern to the malicious domain and the volume of outbound connections on port 443. Unlike DNS logs, NetFlow captures the actual connection attempts regardless of DNS resolution, making it ideal for identifying regular, repetitive outbound flows.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
DNS logs from the internal DNS server.
Why it's wrong here
Only shows DNS queries, not the actual HTTPS connections.
- ✓
NetFlow records from the border router.
Why this is correct
Shows flow timestamps and destinations; reveals periodic connections.
- ✗
Full packet capture of all outbound traffic.
Why it's wrong here
Too much data; not efficient for pattern detection.
- ✗
Host-based firewall logs.
Why it's wrong here
May not show historical data; limited to local host.
Visual reference
Go deeper
Related to this question
About these practice questions
This 200-201 question is part of Courseiva's 979-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.