Courseiva
Network Intrusion Analysis →mediumMultiple Select

200-201 Network Intrusion Analysis Practice Question

An analyst is investigating a potential malware infection. Which TWO of the following are indicators of command and control (C2) communication?

⚠ Common exam trap

The trap is confusing other malicious activities like scanning or exfiltration with C2; candidates might select options that are indicators of different attack stages.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

DNS queries with long, random subdomains

Option D is correct because DNS queries with long, random subdomains are a classic sign of DNS tunneling or domain generation algorithm (DGA) activity used by malware to reach C2 infrastructure while evading domain reputation filtering. Option E is correct because periodic beaconing to an unusual domain reflects the regular check-in pattern malware uses to receive commands from its C2 server, often at fixed intervals with jitter. Option A is not specific to C2, as large file transfers to a peer host more commonly indicate data exfiltration or normal file sharing rather than command-and-control traffic. Option B is not specific to C2 either, since SYN scans to multiple hosts indicate reconnaissance or port scanning activity, not an established C2 channel. Option C is not an indicator of C2 because regular HTTP requests to a known update server are typical of legitimate software update behavior.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Large file transfers to a peer host

    Why it's wrong here

    Large transfers to a peer host suggest exfiltration or peer-to-peer sharing, not the periodic beaconing typical of C2. It is tempting because bulk data movement signals compromise, and it would be correct if the question asked about data exfiltration rather than command and control.

  • ✗

    SYN scans to multiple hosts

    Why it's wrong here

    SYN scans to multiple hosts indicate reconnaissance or lateral movement, not a compromised host beaconing to its controller. It is tempting because scanning is malicious network activity, and it would be the correct indicator if the question asked about internal discovery or port-scanning behaviour.

  • ✗

    Regular HTTP requests to a known update server

    Why it's wrong here

    Regular HTTP requests to a legitimate update server describe normal patching traffic, not covert C2 beaconing. It is tempting because periodic HTTP callbacks resemble beaconing, and it would be correct if the destination were an unknown or suspicious external host rather than a known update server.

  • ✓

    DNS queries with long, random subdomains

    Why this is correct

    Long, random subdomains indicate DNS tunnelling, where malware encodes stolen data or instructions within query names to bypass perimeter controls. This satisfies the C2 detection requirement because the victim resolves high-entropy domains belonging to an attacker-controlled authoritative nameserver, revealing beaconing traffic that standard domain reputation filtering would miss.

  • ✓

    Periodic beaconing to an unusual domain

    Why this is correct

    Beaconing is repeated, timed outbound contact with an attacker-controlled domain, letting infected hosts poll for instructions. The regular interval and unusual destination distinguish it from normal browsing traffic, directly satisfying the C2 indicator the analyst must identify.

About these practice questions

One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.