Courseiva

200-201 Network Intrusion Analysis Practice Question

An intrusion detection system alerts on traffic that appears to be a command and control (C2) beacon. Which of the following characteristics is most typical of beaconing traffic?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Periodic connections at regular intervals to an external IP

Beaconing is characterized by regular, periodic connections to a C2 server at consistent intervals.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Large data transfers to a known cloud provider

    Why it's wrong here

    Beaconing consists of small, periodic check-in packets, not bulk exfiltration; large transfers to cloud providers describe data staging or exfiltration activity. It is tempting because both indicate compromise, but the distinguishing mechanism is timing regularity and payload size, which this option misstates.

  • ✗

    ICMP echo requests to multiple hosts

    Why it's wrong here

    ICMP echo requests to multiple hosts describe network reconnaissance or ping sweeps, not C2 beaconing, which uses repeated connections to a single external endpoint. It is tempting because both are suspicious network patterns, but beaconing's defining mechanism is periodic callback to one controller.

  • ✗

    Random intervals with varying packet sizes

    Why it's wrong here

    Beaconing uses regular, predictable intervals with small, consistent packet sizes; random intervals and varying sizes describe normal or evasive traffic instead. It is tempting because jitter can be added to evade detection, but the typical signature remains periodic timing, which this option contradicts.

  • ✓

    Periodic connections at regular intervals to an external IP

    Why this is correct

    Beaconing malware checks in with its command and control server on a fixed schedule, producing repeated connections to the same external IP at consistent intervals. This regularity, rather than payload content or port choice, is the defining signature analysts use to distinguish beaconing from normal traffic.

About these practice questions

Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.