Courseiva
easyMultiple Choice

Detecting Malware Beaconing from Known Malicious Domains — IDS Alert Interpretation

A NetFlow analysis shows a single internal host communicating with many external IP addresses on port 443, but the traffic volumes are very low (small packets). What is the most likely explanation?

⚠ Common exam trap

Cisco often tests the distinction between 'many destinations with low volume' (C2 beaconing) and 'many destinations with high volume' (normal web browsing or data exfiltration), trapping candidates who overlook the packet size and volume clues.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

C2 communication

The combination of a single internal host communicating with many external IPs on port 443 (HTTPS) with very low traffic volumes and small packets is a classic indicator of command-and-control (C2) beaconing. C2 malware often uses HTTPS to blend in with legitimate web traffic, but the small, periodic packets (e.g., keep-alive or heartbeat messages) distinguish it from normal web browsing, which would involve larger data transfers and consistent payload sizes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Phishing

    Why it's wrong here

    Phishing is an initial-access vector delivered by email or a lure, not a traffic pattern of many low-volume 443 connections; the observed beaconing indicates command-and-control. It is tempting because phishing also involves external HTTPS contact, and it would be correct if the evidence were a malicious link or attachment rather than flow behaviour.

  • ✗

    Web browsing

    Why it's wrong here

    Web browsing generates larger, asymmetric transfers with sustained sessions and repeated destinations, not uniformly tiny packets to many distinct external addresses. It is tempting because port 443 is HTTPS, so normal user traffic appears on this port, and browsing would be the answer if volumes were substantial and destinations few.

  • ✗

    Port scanning

    Why it's wrong here

    Port scanning typically sweeps many destination ports on few hosts, not many external addresses on a single port; low-volume 443 flows to numerous destinations indicate beaconing. Scanning is tempting because it also produces many short, small connections, and it would fit a host contacting many addresses across varied ports.

  • ✓

    C2 communication

    Why this is correct

    Malware beacons often use low-volume periodic connections on port 443.

About these practice questions

Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.