200-201 Security Monitoring Practice Question
An analyst is investigating a potential data exfiltration incident. The only available data is NetFlow records from Cisco routers. Which NetFlow field would be most useful to identify large outbound transfers to an unusual external host?
⚠ Common exam trap
The trap here is focusing on connection-oriented fields like TCP flags or ports, which indicate the nature of the connection but not the volume of data transferred.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Destination IP address and byte count
NetFlow records capture metadata about flows, including source/destination IP, ports, protocol, and byte/packet counts. To detect large outbound transfers to an unusual external host, the analyst should focus on the destination IP address and the byte count. A high byte count from an internal host to an external IP that is not a known service indicates potential exfiltration. Other fields like source port, TCP flags, or interface information provide context but are not as directly useful for identifying data volume.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Input interface and output interface
Why it's wrong here
Interface information helps determine the path of traffic but does not reveal the volume or destination of data. While useful for network mapping, it does not directly indicate exfiltration. The combination of destination IP and byte count is far more useful for identifying large outbound transfers.
- ✗
Next-hop IP address and autonomous system number
Why it's wrong here
Next-hop and AS number provide routing context but do not show how much data is being transferred. They can help identify the external network but not the volume. For exfiltration, the byte count and destination IP are the key fields to examine in NetFlow records.
- ✓
Destination IP address and byte count
Why this is correct
NetFlow records include source/destination IP, ports, protocol, and byte/packet counts. To identify large outbound transfers, the destination IP and byte count are critical. An unusual external host receiving a high volume of bytes from an internal host suggests exfiltration. Other fields like source port or TCP flags are less directly indicative of data volume.
- ✗
Source port and TCP flags
Why it's wrong here
Source port and TCP flags can help identify the type of connection (e.g., SYN, ACK) but do not directly show data volume. While flags can indicate connection state, they are not the primary field for detecting large transfers. The byte count and destination IP are more relevant for exfiltration analysis.
Go deeper
Related to this question
About these practice questions
One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.