200-201 Network Intrusion Analysis Practice Question
An analyst is investigating a potential malware infection. Which TWO of the following are indicators of command and control (C2) communication?
⚠ Common exam trap
The trap is confusing other malicious activities like scanning or exfiltration with C2; candidates might select options that are indicators of different attack stages.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
DNS queries with long, random subdomains
Option D is correct because DNS queries with long, random subdomains are a classic sign of DNS tunneling or domain generation algorithm (DGA) activity used by malware to reach C2 infrastructure while evading domain reputation filtering. Option E is correct because periodic beaconing to an unusual domain reflects the regular check-in pattern malware uses to receive commands from its C2 server, often at fixed intervals with jitter. Option A is not specific to C2, as large file transfers to a peer host more commonly indicate data exfiltration or normal file sharing rather than command-and-control traffic. Option B is not specific to C2 either, since SYN scans to multiple hosts indicate reconnaissance or port scanning activity, not an established C2 channel. Option C is not an indicator of C2 because regular HTTP requests to a known update server are typical of legitimate software update behavior.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Large file transfers to a peer host
Why it's wrong here
Large transfers to a peer host suggest exfiltration or peer-to-peer sharing, not the periodic beaconing typical of C2. It is tempting because bulk data movement signals compromise, and it would be correct if the question asked about data exfiltration rather than command and control.
- ✗
SYN scans to multiple hosts
Why it's wrong here
SYN scans to multiple hosts indicate reconnaissance or lateral movement, not a compromised host beaconing to its controller. It is tempting because scanning is malicious network activity, and it would be the correct indicator if the question asked about internal discovery or port-scanning behaviour.
- ✗
Regular HTTP requests to a known update server
Why it's wrong here
Regular HTTP requests to a legitimate update server describe normal patching traffic, not covert C2 beaconing. It is tempting because periodic HTTP callbacks resemble beaconing, and it would be correct if the destination were an unknown or suspicious external host rather than a known update server.
- ✓
DNS queries with long, random subdomains
Why this is correct
Long, random subdomains indicate DNS tunnelling, where malware encodes stolen data or instructions within query names to bypass perimeter controls. This satisfies the C2 detection requirement because the victim resolves high-entropy domains belonging to an attacker-controlled authoritative nameserver, revealing beaconing traffic that standard domain reputation filtering would miss.
- ✓
Periodic beaconing to an unusual domain
Why this is correct
Beaconing is repeated, timed outbound contact with an attacker-controlled domain, letting infected hosts poll for instructions. The regular interval and unusual destination distinguish it from normal browsing traffic, directly satisfying the C2 indicator the analyst must identify.
Go deeper
Related to this question
About these practice questions
One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.