easyMultiple SelectObjective-mapped
200-201 Practice Question: An analyst is investigating a host that was…
An analyst is investigating a host that was compromised via a web exploit. The analyst has a pcap file of the network traffic. Which TWO pieces of evidence would indicate that the attacker established a persistent backdoor?
⚠ Common exam trap
Cisco often tests the distinction between network-based evidence (pcap) and host-based evidence (registry changes), so candidates may incorrectly select Option C because they confuse persistence mechanisms with the type of data available in a packet capture.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Regular beaconing to an external IP on a high port
Regular beaconing to an external IP on a high port (Option B) is a classic indicator of a persistent backdoor because the compromised host periodically initiates outbound connections to a command-and-control (C2) server, often using non-standard high ports (e.g., 4444, 8080, or 1337) to evade firewall rules. This behavior maintains a communication channel that allows the attacker to issue commands or exfiltrate data over time, even if the initial exploit vector is patched.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A single large file upload to a cloud service
Why it's wrong here
A single upload suggests data exfiltration but does not indicate a persistent backdoor; it may be a one-time event.
- ✓
Regular beaconing to an external IP on a high port
Why this is correct
Regular beaconing is a hallmark of persistent C2 communication, indicating a backdoor that periodically checks in.
- ✗
A change in the host's registry
Why it's wrong here
A registry change is a host-based indicator, not visible in a network pcap, and is not a direct network evidence.
- ✗
An SSH connection from an external IP
Why it's wrong here
An SSH connection could be legitimate remote access and does not by itself indicate a persistent backdoor.
- ✓
DNS queries with subdomains that encode data
Why this is correct
DNS tunneling using encoded subdomains is a technique for persistent covert communication and data exfiltration.
Go deeper
Related to this question
About these practice questions
This 200-201 question is part of Courseiva's 979-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.