200-201 Network Intrusion Analysis Practice Question
During an incident response, an analyst finds evidence of lateral movement. Which THREE of the following are common techniques used for lateral movement?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Remote Desktop Protocol (RDP) connections
SMB authentication attempts, pass-the-hash, and RDP are common lateral movement techniques.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Remote Desktop Protocol (RDP) connections
Why this is correct
RDP gives an attacker an interactive graphical session on a remote host once valid credentials are obtained, enabling direct control of additional systems. That remote-access mechanism moves the intrusion sideways across the estate, matching the stem's lateral movement evidence.
- ✓
SMB authentication attempts across multiple hosts
Why this is correct
SMB authentication attempts spread across many hosts reveal an attacker using file-share logons to reach further systems, often with harvested credentials. This host-to-host authentication pattern is a recognised lateral movement technique, fitting the stem's incident response findings.
- ✗
DNS tunneling
Why it's wrong here
DNS tunneling is typically C2 or exfiltration.
- ✓
Pass-the-hash attacks
Why this is correct
Pass-the-hash reuses captured NTLM password hashes to authenticate to remote systems without cracking the plaintext, letting an attacker hop between hosts using stolen credentials. This credential-reuse mechanism is a classic lateral movement technique, matching the stem's incident scenario.
- ✗
ICMP echo requests
Why it's wrong here
ICMP echo requests are diagnostic reachability probes; they neither authenticate to nor execute on remote hosts, so they cannot move an attacker's foothold. Lateral movement uses SMB, RDP, WMI or PsExec. ICMP would be correct for host discovery or network mapping during reconnaissance.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.