mediumMultiple ChoiceObjective-mapped
200-201 Practice Question: During a security incident, an analyst captures…
During a security incident, an analyst captures network traffic and observes multiple connections from an internal host to a remote IP on port 4444, with irregular packet timing and small payloads. Which type of activity is most likely indicated?
⚠ Common exam trap
Cisco often tests the distinction between C2 beaconing and DNS tunneling by presenting port 4444 (a common C2 port) and irregular timing, hoping candidates confuse it with DNS tunneling because both can use small payloads, but DNS tunneling specifically leverages DNS protocol fields and port 53, not a direct TCP connection on a high port.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
C2 beaconing
The observed traffic—multiple connections from an internal host to a remote IP on TCP port 4444, with irregular timing and small payloads—is a classic signature of command-and-control (C2) beaconing. Attackers often use non-standard high ports like 4444 to evade detection, and the irregular intervals (jitter) are intentionally introduced to avoid pattern-based anomaly detection, while small payloads minimize data transfer and reduce the chance of triggering network thresholds.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
C2 beaconing
Why this is correct
Beaconing involves regular small packets to a command-and-control server.
- ✗
DNS tunneling
Why it's wrong here
DNS tunneling uses DNS protocol on port 53, not port 4444.
- ✗
File transfer
Why it's wrong here
File transfers typically have larger payloads and less frequent connections.
- ✗
VoIP communication
Why it's wrong here
VoIP uses consistent packet timing and specific codecs.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-201 question from scratch — 979 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.