Courseiva
Security Monitoring →hardMultiple Choice

200-201 Security Monitoring Practice Question

An analyst is investigating a potential data exfiltration incident. The only available data is NetFlow records from Cisco routers. Which NetFlow field would be most useful to identify large outbound transfers to an unusual external host?

⚠ Common exam trap

The trap here is focusing on connection-oriented fields like TCP flags or ports, which indicate the nature of the connection but not the volume of data transferred.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Destination IP address and byte count

NetFlow records capture metadata about flows, including source/destination IP, ports, protocol, and byte/packet counts. To detect large outbound transfers to an unusual external host, the analyst should focus on the destination IP address and the byte count. A high byte count from an internal host to an external IP that is not a known service indicates potential exfiltration. Other fields like source port, TCP flags, or interface information provide context but are not as directly useful for identifying data volume.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Input interface and output interface

    Why it's wrong here

    Interface information helps determine the path of traffic but does not reveal the volume or destination of data. While useful for network mapping, it does not directly indicate exfiltration. The combination of destination IP and byte count is far more useful for identifying large outbound transfers.

  • ✗

    Next-hop IP address and autonomous system number

    Why it's wrong here

    Next-hop and AS number provide routing context but do not show how much data is being transferred. They can help identify the external network but not the volume. For exfiltration, the byte count and destination IP are the key fields to examine in NetFlow records.

  • ✓

    Destination IP address and byte count

    Why this is correct

    NetFlow records include source/destination IP, ports, protocol, and byte/packet counts. To identify large outbound transfers, the destination IP and byte count are critical. An unusual external host receiving a high volume of bytes from an internal host suggests exfiltration. Other fields like source port or TCP flags are less directly indicative of data volume.

  • ✗

    Source port and TCP flags

    Why it's wrong here

    Source port and TCP flags can help identify the type of connection (e.g., SYN, ACK) but do not directly show data volume. While flags can indicate connection state, they are not the primary field for detecting large transfers. The byte count and destination IP are more relevant for exfiltration analysis.

About these practice questions

One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.