mediumMultiple Choice
200-201 Practice Question: During a security incident, an analyst captures…
During a security incident, an analyst captures network traffic and observes multiple connections from an internal host to a remote IP on port 4444, with irregular packet timing and small payloads. Which type of activity is most likely indicated?
⚠ Common exam trap
Cisco often tests the distinction between C2 beaconing and DNS tunneling by presenting port 4444 (a common C2 port) and irregular timing, hoping candidates confuse it with DNS tunneling because both can use small payloads, but DNS tunneling specifically leverages DNS protocol fields and port 53, not a direct TCP connection on a high port.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
C2 beaconing
The observed traffic—multiple connections from an internal host to a remote IP on TCP port 4444, with irregular timing and small payloads—is a classic signature of command-and-control (C2) beaconing. Attackers often use non-standard high ports like 4444 to evade detection, and the irregular intervals (jitter) are intentionally introduced to avoid pattern-based anomaly detection, while small payloads minimize data transfer and reduce the chance of triggering network thresholds.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
C2 beaconing
Why this is correct
Port 4444 with regular small payloads and jittered timing matches beaconing, where infected hosts poll a command-and-control server for instructions. The irregular intervals evade simple threshold detection, and the low data volume distinguishes it from bulk exfiltration or normal interactive traffic.
- ✗
DNS tunneling
Why it's wrong here
DNS tunneling uses DNS protocol on port 53, not port 4444.
- ✗
File transfer
Why it's wrong here
Port 4444 with irregular timing and small payloads indicates command-and-control beaconing, not bulk data movement. File transfer would show sustained high-volume flows with consistent packet sizes and throughput. The small, jittered payloads exist to evade detection while maintaining periodic check-ins, which is the opposite traffic profile from transferring files.
- ✗
VoIP communication
Why it's wrong here
VoIP uses UDP with RTP streams on defined port ranges and steady packet cadence, not repeated TCP connections to port 4444 with irregular timing. VoIP analysis applies when diagnosing call quality or signalling on SIP and RTP traffic.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.