Courseiva

200-201 · domain

Network Intrusion Analysis

This domain covers reading packets and logs to spot malicious activity: using tools like Wireshark and tcpdump to pull files from PCAPs, recognizing exfiltration and command-and-control patterns in DNS, FTP, and HTTP traffic, and mapping observed behavior to the Cyber Kill Chain. Questions give you a traffic scenario and ask for the correct interpretation or tool.

122 questions26 easy58 medium38 hard

Focused practice

Practice Network Intrusion Analysis questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Network Intrusion Analysis

Be able to open a PCAP, extract transferred files, and classify traffic as normal or malicious. The most important skill is distinguishing exfiltration from command-and-control and naming the correct Cyber Kill Chain phase for the evidence.

Extracting transferred files from a PCAP using Wireshark's export objects or tcpdump

Identifying data exfiltration over FTP, HTTP, or DNS by volume, direction, and timing

Recognizing DNS tunneling via high-entropy or base64-encoded subdomain labels

Mapping observed network activity to the correct Cyber Kill Chain phase

Watch out for

Common Network Intrusion Analysis exam traps

  • ▸Assuming any large transfer is exfiltration; direction, timing, and source host role determine whether it is malicious.
  • ▸Confusing DNS tunneling with normal CDN or load-balancer subdomains; look for encoded or high-entropy labels, not just many queries.
  • ▸Picking the wrong Kill Chain phase: exfiltration is data leaving, while command-and-control is beaconing or instructions.

Question index

All Network Intrusion Analysis questions (122)

Click any question to see the full explanation, or start a practice session above.

1

An analyst detects HTTPS traffic to a domain that was registered only 24 hours ago and has no web content. The traffic occurs at odd hours and with consistent packet sizes. What technique is likely being used for C2?

Easy
2

A SOC analyst is investigating a suspected network intrusion and reviews NetFlow records. The analyst observes a sudden increase in outbound traffic from a single internal host to an external IP address, with large data volumes during off-hours. Which two additional indicators should the analyst examine to confirm data exfiltration? (Choose two.)

Medium
3

Which of the following is a common indicator of DNS tunneling used for exfiltration?

Medium
4

A SOC analyst is reviewing a packet capture from an internal web server and notices that a single external IP sent 4,000 TCP segments with the ACK flag set to a closed port, and each segment received a RST response. No SYN packets preceded these segments. Which type of scan is this host most likely performing?

Medium
5

An analyst is triaging a suspected FTP brute-force campaign against an internal server. The IDS reports many failed authentication attempts from a single external address. Which TWO data points, gathered from the FTP server and network logs, most directly support confirming and characterizing the attack? (Choose two.)

Hard
6

A security analyst is investigating an alert that indicates a potential SQL injection attack. Which of the following HTTP request patterns is most indicative of a SQL injection attempt?

Easy
7

An analyst identifies a series of SMB authentication attempts from a compromised host to multiple internal servers. The authentication uses NTLM hashes. Which TWO techniques are most likely being used for lateral movement? (Select 2)

Medium
8

An IDS alert indicates that a server received HTTP requests containing long strings of the form ../../../../etc/passwd in a URL parameter. The web server returned HTTP 200 responses to these requests. Which conclusion should the analyst draw while continuing the investigation?

Medium
9

Which Wireshark filter can be used to extract the full TCP data of a specific conversation from a PCAP?

Medium
10

An analyst is examining a PCAP file for signs of lateral movement. Which TWO of the following are typical indicators of lateral movement using pass-the-hash?

Medium
11

During network intrusion analysis, an analyst reviews logs and observes an alert for a TCP SYN scan. Which characteristic of a SYN scan would the analyst look for in packet captures?

Easy
12

In network forensics, which Wireshark filter would be used to reconstruct a TCP conversation between two hosts?

Easy
13

An analyst is reviewing PCAP and sees a TCP stream with a Wireshark filter 'tcp.stream eq 0'. The conversation shows an interactive shell session with commands like 'whoami' and 'ls'. This is most likely evidence of what?

Medium
14

An analyst is investigating a potential DNS tunneling attack. Which characteristic in DNS traffic would most likely indicate DNS tunneling?

Easy
15

In a PCAP analysis, an analyst uses the filter 'http.request.uri contains "UNION"' and finds multiple HTTP requests with 'SELECT' and 'UNION SELECT' in the URI parameter. Which type of attack is likely occurring?

Easy
16

An analyst is reviewing a PCAP and observes a TCP stream where the client sends a packet with the PSH and ACK flags set, containing an HTTP GET request. The server responds with a packet with the FIN and ACK flags set, but the client continues to send data. Later, the client sends a packet with the RST flag set. Which statement best describes what is happening?

Hard
17

An analyst is examining a PCAP and sees a series of TCP packets where the client sends a SYN, receives a SYN-ACK, and then sends an ACK. Immediately after, the client sends a packet with the RST flag set, terminating the connection before any application data is exchanged. This pattern repeats across many destination ports on the same server. Which activity does this most likely represent?

Hard
18

During an intrusion investigation, an analyst needs to determine whether a specific internal host communicated with a known malicious IP address. The analyst has full packet capture for the relevant window but only wants to see the TCP stream from that host to the suspect address. Which Wireshark display filter isolates that conversation?

Easy
19

An analyst reviews network logs and sees a large outbound FTP transfer of 500 MB from a workstation to an external IP at 2:00 AM. The workstation regularly sends 10 MB daily. What should the analyst suspect?

Medium
20

An analyst notices that an internal host is sending periodic ICMP echo requests to an external IP, and the echo replies contain payloads that are longer than the default Windows ping payload. The payload bytes appear to be encoded and change with each reply. Which activity is most likely occurring?

Medium
21

During alert triage, an analyst determines that an alert fired but no actual attack or malicious activity occurred on the network. How should this alert be classified?

Easy
22

An alert shows a high volume of outbound traffic from an internal host to an external IP using FTP. The data includes files with names matching internal document names. This activity is most likely:

Hard
23

An analyst examining a PCAP sees a host send an HTTP GET request where the User-Agent string contains a long, random-looking hexadecimal value, the request path includes a similarly random string, and the server responds with a 404 status code but a response body of several kilobytes. This pattern repeats every 60 seconds. Which activity is most likely occurring?

Hard
24

A SOC analyst is investigating a suspected ARP poisoning attack on a local subnet. Which two indicators would most strongly support this conclusion? (Choose two.)

Hard
25

An analyst is reviewing alerts from an IDS. A signature matched 'script' and 'alert' in HTTP request parameters. The analyst inspects the packet and sees <script>alert('XSS')</script> in the URI. What is the most accurate classification of this alert?

Medium
26

While reviewing firewall logs, an analyst notices repeated inbound connections from a single external IP to multiple internal hosts on TCP port 3389 within a short time window. Each connection lasts only a few seconds and is followed by a new connection to a different internal host. Which activity does this pattern most likely represent?

Easy
27

A junior analyst is asked to identify which log source would best confirm that an internal workstation attempted to resolve a suspicious domain shortly before an alert fired. The environment forwards DNS query logs from its recursive resolvers to the SIEM. Which action should the analyst take first?

Easy
28

An analyst is investigating a suspected ARP poisoning attack on a local subnet. The analyst captures traffic and reviews ARP packets. Which two characteristics would most likely indicate that ARP poisoning is occurring? (Choose two.)

Medium
29

A security analyst notices that an internal web server is receiving HTTP requests where the User-Agent string is identical across thousands of requests originating from a single external IP address, and each request targets a different URL path on the server. The requests occur at a rate of several hundred per second. Which activity does this pattern most likely represent?

Easy
30

During a network intrusion analysis, a security analyst observes repeated TCP SYN packets sent to a range of ports on a target host, each followed by an RST response. No subsequent ACK packets are observed. Which phase of the Cyber Kill Chain is the attacker most likely executing?

Medium
31

An analyst is investigating a potential malware infection. Which TWO of the following are indicators of command and control (C2) communication?

Medium
32

An analyst observes a series of DNS queries for subdomains like 'ZGVzdGluYXRpb24= .malicious.com' where the subdomain part appears base64-encoded. The volume of DNS traffic from a single host is unusually high. Which exfiltration technique is most likely in use?

Medium
33

A SOC analyst is reviewing a PCAP captured at the perimeter firewall. The analyst notices that a single internal host has sent TCP segments with the FIN, PSH, and URG flags all set simultaneously to multiple destination ports on several external hosts. No corresponding ACK, SYN, or RST packets are observed in the capture. Which type of scan is the analyst most likely observing?

Medium
34

An analyst reviewing network alerts notices a rule triggered for 'ET SCAN NMAP -sU scan' based on traffic to a Linux server. The packet capture shows multiple UDP packets to various ports, and for closed ports, the server responds with ICMP Destination Unreachable (Port Unreachable). Which type of scan is being performed, and how should the analyst classify this alert?

Hard
35

An analyst examines PCAP and sees multiple SMB sessions from internal host 10.1.1.10 to 10.1.1.20, 10.1.1.30, and 10.1.1.40 within seconds. The NTLM authentication contains a hash parameter that is identical across sessions. Which lateral movement technique is most likely being used?

Hard
36

An analyst is reviewing PCAP from a network intrusion. The attacker used a payload with ROP gadgets and shellcode. Which TWO exploitation indicators are associated with this attack? (Choose two.)

Hard
37

A security analyst observes repeated ICMP port unreachable responses from a target host. The source IP is sending packets to multiple UDP ports. Which type of scan is most likely being performed?

Easy
38

During a network intrusion analysis, an analyst observes a series of TCP packets with the FIN flag set but no corresponding ACK, followed by packets with the RST flag set. What is the most likely explanation for this traffic pattern?

Hard
39

During a network intrusion investigation, an analyst notices repeated SMB authentication attempts from a single host to multiple other hosts using different usernames. Which type of activity does this pattern suggest?

Medium
40

During an incident, an analyst observes the following in PCAP: (1) DNS queries with random-looking subdomains to a known malicious domain, (2) large outbound FTP transfers of .zip files, (3) HTTP POST requests with Base64-encoded data in the body. Which THREE exfiltration techniques are being used? (Select 3)

Hard
41

A security analyst observes a large number of SYN packets sent to various ports on a target host, receiving RST responses for closed ports and no response for open ports. Which phase of the Cyber Kill Chain does this activity represent?

Medium
42

A SOC analyst monitors outbound traffic from a corporate network and notices a single internal host contacting an external server on TCP port 53, but the payloads contain fixed-length, non-DNS binary data with no query/response structure. The host also makes outbound connections to the same external IP on TCP port 4444. Which technique is the attacker most likely using?

Medium
43

A SOC analyst is triaging an alert from a network sensor indicating that an internal host may be performing host discovery on the local subnet. The analyst wants to identify active hosts without generating TCP connections. Which two techniques should the analyst expect to see in the packet capture that are consistent with this goal? (Choose two.)

Medium
44

An analyst identifies a PCAP with a reverse shell session. Which characteristic in the traffic would most likely indicate an interactive shell session?

Hard
45

During an investigation, an analyst observes that a workstation resolves an internal hostname to an IP address that does not match the DHCP lease record, and subsequent SMB connections to that hostname reach an attacker-controlled server. Which attack technique best explains this behavior?

Hard
46

During a forensic analysis, an analyst uses NetworkMiner to extract files from a PCAP. One of the extracted files contains a PE executable with a known signature of a malware variant. Which phase of the Cyber Kill Chain does the file transfer most likely represent?

Hard
47

An analyst is investigating a suspected SQL injection attack captured in a PCAP. The analyst needs to identify TWO indicators in the HTTP traffic that would confirm a SQL injection attempt. Which two indicators should the analyst look for? (Choose two.)

Hard
48

An analyst notices periodic HTTP GET requests to a suspicious domain every 60 seconds. The payload size is small and consistent. This behavior is characteristic of which phase of the Cyber Kill Chain?

Medium
49

A SOC analyst notices an internal host transmitting a series of ICMP Echo Request packets to an external IP, each with a payload size of exactly 1024 bytes and a repeating pattern. The echo replies are consistently the same size. Which type of activity does this most likely indicate?

Medium
50

An analyst monitoring an internal network observes a host sending a large number of TCP segments with the URG flag set and a non-zero urgent pointer, but the urgent pointer value does not point to actual urgent data. The destination host appears to be processing the data normally. Which explanation best describes what the analyst is observing?

Hard
51

An analyst inspects a PCAP and sees an internal host sending HTTP requests where the User-Agent string is unusually long and contains random alphanumeric characters, and the Cookie header carries base64-like data to an external server. The server responds with small HTTP 200 OK messages. Which technique is most consistent with this traffic?

Hard
52

While analyzing a PCAP, an analyst uses the Wireshark filter 'http.request' and finds a URI parameter containing '%27%20UNION%20SELECT%201,2,3%20--'. What type of attack is indicated?

Medium
53

A network analyst is examining a PCAP and sees a large number of ICMP echo request packets sent from a single internal host to multiple external IP addresses, with varying payload sizes and no corresponding echo replies. The analyst suspects the host is being used for reconnaissance or data exfiltration. Which characteristic of the ICMP traffic would most strongly indicate that it is being used for data exfiltration rather than simple reconnaissance?

Easy
54

A SOC analyst sees an alert for 'Possible SQL Injection' on a web server. Reviewing the PCAP, the analyst finds the parameter 'id=1 OR 1=1' in the HTTP request. However, the web server returns a normal page with no signs of compromise. What is the correct classification?

Medium
55

An analyst examines a PCAP and observes that an internal host sends an ICMP echo request containing a payload of 1200 bytes, followed by an ICMP echo reply from an external host with a payload of 1500 bytes. The payload data does not match standard ping patterns and appears to contain encoded file fragments. Which technique is most consistent with this observation?

Hard
56

A SOC analyst is analyzing a PCAP from a suspected intrusion. The traffic shows a series of TCP connections where the client sends a SYN, receives a SYN-ACK, then immediately sends a RST instead of an ACK, and this pattern repeats across multiple ports on the same target. Which type of scan is most likely being performed?

Medium
57

An intrusion detection system alerts on HTTP traffic containing the string 'UNION SELECT' in the URI parameter. This is most indicative of what type of attack?

Hard
58

A PCAP contains an HTTP POST request with a parameter containing "UNION SELECT username, password FROM users". This is evidence of:

Medium
59

A network analyst is examining a PCAP and notices a series of TCP packets with the PSH flag set and small payload sizes, sent from an internal host to an external IP. The external IP responds with similar small packets. The communication is continuous and occurs at regular intervals. Which type of activity is most likely occurring?

Medium
60

An analyst reviews PCAP traffic and sees a series of HTTP POST requests from an internal host to an external IP at exactly 60-second intervals. The payload size is consistent. Which phase of the Cyber Kill Chain does this activity most likely represent?

Medium
61

An analyst reviews an IDS alert indicating a TCP SYN scan against a web server. The analyst wants to confirm the scan by examining packet-level evidence in the PCAP. Which TWO characteristics would confirm a SYN scan rather than legitimate client behavior? (Choose two.)

Medium
62

An analyst is reviewing a PCAP and sees multiple HTTP requests with the parameter 'id=1 UNION SELECT username,password FROM users'. What type of attack is being attempted?

Medium
63

During incident response, an analyst extracts files from a PCAP using Wireshark's Export Objects feature. One extracted file is a PDF that triggers an IDS alert for 'Exploit:PDF/HeapSpray'. Which technique does this alert describe?

Hard
64

A security analyst observes periodic outbound HTTPS connections to an unusual domain that resolves to different IP addresses each time. This behavior is most indicative of:

Medium
65

A security analyst is investigating a potential exploit. The PCAP shows a HTTP POST request containing a long string of characters that, when decoded, reveals a series of return-oriented programming (ROP) gadgets. What is the likely purpose of this payload?

Hard
66

An analyst is investigating an alert for a potential ICMP tunneling attack. The analyst reviews a PCAP and notices a series of ICMP Echo Request packets with unusually large payloads (over 1000 bytes) and varying payload contents, sent from an internal host to an external IP address. The external host replies with ICMP Echo Reply packets of similar size. Which characteristic most strongly supports the conclusion that this is ICMP tunneling rather than normal ping traffic?

Medium
67

An analyst detects an attack where the attacker uses NTLM authentication with a hashed password instead of the plaintext password. This technique is known as:

Hard
68

A SOC analyst is reviewing a PCAP captured at the network perimeter. The analyst notices that a single internal host sends a series of ICMP echo requests to multiple external hosts, but the ICMP payload size is unusually large (over 1000 bytes) and the payload contains non-ASCII, high-entropy data. The echo replies from the external hosts are also large and contain similar data. Which type of activity is most likely occurring?

Medium
69

An analyst is examining a PCAP of what appears to be a covert channel. The analyst observes that the internal host sends ICMP Echo Requests that contain a payload of exactly 48 bytes of non-repeating binary data, and the corresponding Echo Replies always return with a zero-length payload. The payload bytes, when decoded, contain what looks like command strings. Which technique is most consistent with these observations?

Hard
70

In a PCAP, an analyst sees a large outbound data transfer over FTP to an external IP address during non-business hours. The source host is a database server. Which phase of the Cyber Kill Chain does this represent?

Medium
71

A network analyst finds a PCAP with a series of DNS queries for subdomains like "data12345.example.com" and "data67890.example.com" where the subdomain names appear to contain encoded base64 data. This pattern suggests:

Hard
72

An analyst receives an alert for 'ET WEB_SERVER Possible SQL Injection Attempt' triggered by a URL parameter containing ' OR 1=1--'. After investigating, the analyst confirms that the web application is not vulnerable to SQL injection and the request was a benign test. How should this alert be classified?

Easy
73

An analyst is investigating a PCAP file and wants to reconstruct a conversation between two hosts. Which Wireshark filter would be most appropriate to follow the entire TCP stream?

Medium
74

In a PCAP, an analyst sees an interactive shell session over TCP with irregular command prompts and responses. Which tool was likely used to generate this traffic?

Hard
75

During a PCAP analysis, a security analyst notices an HTTP request with the URI parameter 'id=1 UNION SELECT username,password FROM users--'. What is the most likely attack being attempted?

Hard
76

In the MITRE ATT&CK framework, TTPs are mapped to:

Easy
77

During an intrusion analysis, an analyst identifies that an attacker used a domain generation algorithm (DGA) to resolve C2 domains. Which of the following traffic patterns is most consistent with DGA?

Medium
78

An analyst observes a large outbound FTP transfer to an external IP address from a server that normally does not generate such traffic. This is most likely an indicator of:

Hard
79

During a SYN scan, an attacker sends a SYN packet to a closed port on a target. What response does the target typically send back?

Medium
80

A SOC analyst is reviewing NetFlow records and notices that a single internal host has initiated connections to 1,024 distinct destination IP addresses on TCP port 445 within a five-minute window. Each connection attempt lasts under one second and transfers fewer than three packets. Which activity does this pattern most strongly indicate?

Medium
81

In the Cyber Kill Chain model, which phase involves delivering the exploit to the target, such as via email attachment or malicious link?

Easy
82

An analyst filters PCAP with 'tcp.stream eq 0' and sees an interactive shell session with commands like 'whoami', 'ls -la', 'cd /etc'. The session originated from an HTTP POST to a web shell. Which type of attack is this?

Medium
83

An analyst is reviewing a network intrusion alert and sees a large number of ICMP echo requests sent from a single external IP to multiple internal hosts. The ICMP payloads are identical and the requests are sent in rapid succession. Which type of activity does this most likely represent?

Easy
84

An intrusion detection system alerts on traffic that appears to be a command and control (C2) beacon. Which of the following characteristics is most typical of beaconing traffic?

Easy
85

An analyst is monitoring network traffic and observes a host making outbound HTTPS connections to a domain that appears to be generated by a Domain Generation Algorithm (DGA). Which phase of the Cyber Kill Chain best describes this activity?

Medium
86

An analyst examines a PCAP and finds a series of UDP packets sent to multiple ports on a target. The target responds with ICMP 'Destination Unreachable (Port Unreachable)' messages for each port. What type of scan is being performed?

Hard
87

Which type of attack is indicated by a series of SMB authentication attempts from one host to multiple other hosts in a short time frame?

Medium
88

An analyst detects a large outbound FTP transfer from a sensitive server to an external IP address not previously seen. The file being transferred is a compressed archive containing database dumps. Which Cyber Kill Chain phase is most directly indicated?

Hard
89

An analyst is investigating a suspected TCP session hijacking attempt. The analyst reviews a PCAP and sees duplicate packets with the same sequence numbers but different source IP addresses. Which two TCP characteristics would most likely be manipulated in such an attack? (Choose two.)

Medium
90

An analyst is investigating a host that is making outbound HTTPS connections to multiple random-looking domains, each with a short TTL. The domains are not in any threat intelligence feeds. Which technique is most likely being used?

Hard
91

During network intrusion analysis, an analyst reviews a PCAP showing a series of TCP packets where the attacker sends an ACK with a sequence number outside the expected window, followed by packets with overlapping sequence ranges. The analyst suspects the attacker is attempting to evade an IDS by confusing its TCP stream reassembly. Which evasion technique is being used?

Easy
92

An analyst is reviewing a PCAP of an intrusion and observes that the attacker's machine sent a TCP segment with the ACK flag set to a target host, but the target had never received a SYN from the attacker. The target responded with an RST. The analyst wants to determine what the attacker was attempting. Which technique best describes this activity?

Hard
93

An analyst reviews a PCAP and sees a host receive an unsolicited ICMP echo reply containing an embedded payload, followed by the host initiating a TCP connection to an internal server on port 445. The ICMP payload begins with bytes that decode to a URL path. Which analysis conclusion is most defensible?

Hard
94

A network analyst is investigating a suspected DNS tunneling attack. Which THREE of the following are indicators of DNS tunneling?

Medium
95

A security analyst is examining a PCAP and observes a series of TCP packets with the PSH flag set and small payload sizes, sent from an internal host to an external IP. The packets are spaced roughly 30 seconds apart. Which type of malicious activity is MOST likely indicated?

Medium
96

A SOC analyst is investigating a suspected data exfiltration event on a corporate network. The analyst runs a Wireshark display filter on a captured PCAP and sees a large volume of outbound packets from an internal workstation to an external IP address, all with the same destination port and with the TCP PSH flag set on nearly every packet. The payloads are small but consistently sized, and the transfer continues for over 30 minutes. Which statement best explains why this traffic pattern is suspicious in the context of network intrusion analysis?

Medium
97

A threat hunter identifies a binary that uses a Domain Generation Algorithm (DGA) to create domain names like 'eksdghf23.com', 'mzncxv89.net' each day. The malware contacts these domains over HTTPS. Which phase of the Cyber Kill Chain is most directly associated with this technique?

Hard
98

An analyst is investigating lateral movement and observes SMB authentication attempts from host A to multiple other hosts using NTLM authentication with a hash value instead of a password. Which attack technique is most likely being used?

Hard
99

Which TWO of the following are typical indicators of a C2 beaconing communication?

Easy
100

An analyst investigates a suspected data exfiltration event and captures outbound traffic from a compromised host. The traffic uses HTTPS to an unfamiliar external domain and shows consistent large uploads at regular intervals. Which two indicators would most strongly support the conclusion that this is automated exfiltration rather than normal user browsing? (Choose two.)

Medium
101

In the Cyber Kill Chain, which phase involves sending a malicious attachment to a targeted user?

Easy
102

During the Cyber Kill Chain, which phase involves sending a malicious attachment to a target user via email?

Easy
103

An analyst examining a PCAP sees an internal host sending ICMP echo requests where the payload length is consistently 1,100 bytes and the payload bytes change on every packet, while the destination is an external IP that returns echo replies of normal size. The host has no monitoring tool installed and no legitimate reason to send large ICMP. Which technique is most likely being used?

Hard
104

An analyst detects multiple SMB authentication attempts from a single internal host to several other internal hosts using NTLM hashes instead of plaintext passwords. Which technique is most likely being used?

Medium
105

A junior analyst is reviewing a packet capture and sees a workstation repeatedly sending ICMPv4 Type 8 packets to an external IP address with varying payload sizes. The analyst wants to confirm whether this activity is a covert channel. Which characteristic of the ICMP traffic would most strongly suggest that the ICMP payload is being used to exfiltrate data?

Easy
106

During an intrusion analysis, a SOC analyst reviews logs showing an outbound connection from an internal host to an external IP at 03:00 AM every 60 seconds. The traffic is HTTPS to a suspicious domain with a high entropy name. Which phase of the Cyber Kill Chain does this activity represent?

Medium
107

An analyst is examining network alerts for lateral movement. Which TWO of the following are typical indicators of lateral movement using SMB?

Medium
108

A SOC analyst reviewing a packet capture notices that a single internal host has initiated hundreds of short-lived TCP sessions to the same external web server over the past hour, and every session completed a full three-way handshake before being torn down with FIN/ACK. No single session transferred more than a few kilobytes. Which traffic characteristic should the analyst use to classify this activity?

Medium
109

During an incident response, an analyst finds evidence of lateral movement. Which THREE of the following are common techniques used for lateral movement?

Hard
110

An analyst reviews an alert that triggered on a network signature for 'shellcode' in a payload. The payload contains a sequence of NOP sleds followed by executable code. Which type of exploitation technique does this indicate?

Medium
111

During PCAP analysis, a security analyst observes the following pattern: a series of TCP SYN packets to multiple ports on a target, followed by RST packets from the target for closed ports. Which TWO characteristics describe this scan?

Hard
112

An analyst notices that a DNS query for 'www.attacker.com' contains a long subdomain with Base64-encoded data. This activity is observed every 5 minutes. What exfiltration technique is most likely in use?

Medium
113

An analyst inspects a PCAP and finds a TCP stream where the client and server exchange data in alternating small chunks, each packet's payload is roughly 40 to 60 bytes, and the conversation lasts over two hours with consistent inter-packet delays of about ten seconds. The destination port is 443 but the payload is not TLS. Which conclusion is best supported?

Hard
114

An analyst is investigating a suspected FTP brute-force attack. The logs show numerous failed login attempts from a single external IP to multiple user accounts on an internal FTP server. Which two additional pieces of evidence would best confirm a brute-force attack? (Choose two.)

Medium
115

A security analyst is reviewing PCAP data and sees a TCP stream with interactive shell commands such as 'whoami', 'ls -la', and 'cat /etc/passwd'. The session appears to be bidirectional with a remote IP. Which type of attack is most likely occurring?

Medium
116

Which tool can be used to extract files from a PCAP file for further analysis?

Medium
117

A network analyst is reviewing firewall logs and sees repeated inbound connections from a single external IP to TCP port 445 on multiple internal hosts over a short period. The connections are followed by SMB negotiation attempts. Which activity does this most likely represent?

Easy
118

An analyst detects traffic from an internal host that periodically sends small DNS queries to a domain with high entropy subdomains (e.g., 'a3k9f2.example.com'). The domain is not on any blocklist, and the query intervals are consistent every 60 seconds. Which technique is most likely being used?

Medium
119

A security analyst receives an alert for a known malware signature in an outbound file transfer. After investigation, the file is confirmed as benign software. This alert is classified as:

Easy
120

An analyst observes an alert triggered by a single SYN packet to a closed port. The packet did not complete a TCP handshake. What type of attack does this most likely indicate?

Easy
121

During an incident response, an analyst identifies a PCAP containing an HTTP POST request to a suspicious external IP with a large payload. The response is not typical for web applications. What type of activity is most likely occurring?

Medium
122

An analyst is analyzing a PCAP and sees multiple ICMP port unreachable responses from a target host when scanning UDP ports. What does this indicate about the scanned ports?

Medium

Frequently asked questions

What does the Network Intrusion Analysis domain cover on the 200-201 exam?
Be able to open a PCAP, extract transferred files, and classify traffic as normal or malicious. The most important skill is distinguishing exfiltration from command-and-control and naming the correct Cyber Kill Chain phase for the evidence.
How many questions are in this domain?
This page lists all 122 Network Intrusion Analysis questions in the 200-201 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Network Intrusion Analysis questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
cisco-cyberops-associate CISCO-CYBEROPS-ASSOCIATE cbrops intrusion analysis Practice Questions