200-201 Security Monitoring Practice Question
During a security assessment, a SOC analyst notices an IDS/IPS alert with a severity of 'High' for a signature named 'ET TROJAN Win32.Vobfus Checkin'. The alert shows source IP 10.0.0.5 and destination IP 203.0.113.50 on port 443. What is the most likely interpretation of this alert?
⚠ Common exam trap
Cisco often tests the distinction between generic HTTPS traffic and signature-specific malware detection, trapping candidates who assume all encrypted traffic is benign or that high-severity alerts are automatically false positives.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A compromised host attempting to communicate with a command-and-control server over encrypted traffic
The signature 'ET TROJAN Win32.Vobfus Checkin' is a known detection rule for the Vobfus trojan family, which typically establishes command-and-control (C2) communications over HTTPS (port 443) to exfiltrate data or receive instructions. The high severity indicates the IDS/IPS has matched traffic patterns or JA3 hashes associated with this malware's C2 beaconing, making it highly likely that the host at 10.0.0.5 is compromised and communicating with a malicious server at 203.0.113.50.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
A compromised host attempting to communicate with a command-and-control server over encrypted traffic
Why this is correct
The signature and destination IP suggest C2 communication over HTTPS.
- ✗
A false positive due to a web browser accessing a secure site
Why it's wrong here
The signature is specific to a trojan, not typical browser traffic.
- ✗
An attacker scanning for open HTTPS ports on the internal network
Why it's wrong here
The direction is from internal to external, not scanning.
- ✗
A benign HTTPS connection to a legitimate website
Why it's wrong here
The signature is specific to a trojan, not benign.
Go deeper
Related to this question
About these practice questions
One of 979 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.