200-201 Network Intrusion Analysis Practice Question
An intrusion detection system alerts on traffic that appears to be a command and control (C2) beacon. Which of the following characteristics is most typical of beaconing traffic?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Periodic connections at regular intervals to an external IP
Beaconing is characterized by regular, periodic connections to a C2 server at consistent intervals.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Large data transfers to a known cloud provider
Why it's wrong here
Beaconing consists of small, periodic check-in packets, not bulk exfiltration; large transfers to cloud providers describe data staging or exfiltration activity. It is tempting because both indicate compromise, but the distinguishing mechanism is timing regularity and payload size, which this option misstates.
- ✗
ICMP echo requests to multiple hosts
Why it's wrong here
ICMP echo requests to multiple hosts describe network reconnaissance or ping sweeps, not C2 beaconing, which uses repeated connections to a single external endpoint. It is tempting because both are suspicious network patterns, but beaconing's defining mechanism is periodic callback to one controller.
- ✗
Random intervals with varying packet sizes
Why it's wrong here
Beaconing uses regular, predictable intervals with small, consistent packet sizes; random intervals and varying sizes describe normal or evasive traffic instead. It is tempting because jitter can be added to evade detection, but the typical signature remains periodic timing, which this option contradicts.
- ✓
Periodic connections at regular intervals to an external IP
Why this is correct
Beaconing malware checks in with its command and control server on a fixed schedule, producing repeated connections to the same external IP at consistent intervals. This regularity, rather than payload content or port choice, is the defining signature analysts use to distinguish beaconing from normal traffic.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.