Courseiva
Security MonitoringhardMultiple ChoiceObjective-mapped

200-201 Security Monitoring Practice Question

During a security assessment, a SOC analyst notices an IDS/IPS alert with a severity of 'High' for a signature named 'ET TROJAN Win32.Vobfus Checkin'. The alert shows source IP 10.0.0.5 and destination IP 203.0.113.50 on port 443. What is the most likely interpretation of this alert?

⚠ Common exam trap

Cisco often tests the distinction between generic HTTPS traffic and signature-specific malware detection, trapping candidates who assume all encrypted traffic is benign or that high-severity alerts are automatically false positives.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

A compromised host attempting to communicate with a command-and-control server over encrypted traffic

The signature 'ET TROJAN Win32.Vobfus Checkin' is a known detection rule for the Vobfus trojan family, which typically establishes command-and-control (C2) communications over HTTPS (port 443) to exfiltrate data or receive instructions. The high severity indicates the IDS/IPS has matched traffic patterns or JA3 hashes associated with this malware's C2 beaconing, making it highly likely that the host at 10.0.0.5 is compromised and communicating with a malicious server at 203.0.113.50.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • A compromised host attempting to communicate with a command-and-control server over encrypted traffic

    Why this is correct

    The signature and destination IP suggest C2 communication over HTTPS.

  • A false positive due to a web browser accessing a secure site

    Why it's wrong here

    The signature is specific to a trojan, not typical browser traffic.

  • An attacker scanning for open HTTPS ports on the internal network

    Why it's wrong here

    The direction is from internal to external, not scanning.

  • A benign HTTPS connection to a legitimate website

    Why it's wrong here

    The signature is specific to a trojan, not benign.

About these practice questions

One of 979 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.