200-201 Security Monitoring Practice Question
During incident response, an analyst notices that a compromised host is making outbound SMB connections to several internal servers on TCP port 445 using the same domain user account within minutes. Which activity is most likely occurring?
⚠ Common exam trap
The trap here is dismissing the SMB fan-out as routine file share access, when the speed and account reuse point to credential-based lateral movement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Lateral movement using stolen credentials
Rapid outbound SMB connections to multiple internal servers using the same domain account indicate lateral movement with stolen credentials. Attackers use tools like PsExec or built-in SMB to pivot across the network, access shares, and deploy payloads. This behavior should be treated as a high-severity incident, triggering isolation of the source host and a review of the compromised account's activity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Normal user access to multiple file shares
Why it's wrong here
A user accessing several file shares would typically do so over a longer period and from their own workstation, not from a compromised host making rapid connections to multiple servers. The tight timeframe and the focus on port 445 across several internal systems are more consistent with automated lateral movement. Legitimate share access would also align with the user's role and normal working hours.
- ✓
Lateral movement using stolen credentials
Why this is correct
Outbound SMB connections to multiple internal servers on port 445 using a single domain account within a short window strongly suggest lateral movement. Attackers who have compromised one host often use stolen credentials to access file shares or administrative shares on other systems, spreading malware or establishing additional footholds. This pattern is a classic indicator that should trigger immediate containment and credential reset.
- ✗
A backup application scanning file shares
Why it's wrong here
Backup software typically connects to file shares on a scheduled basis, often using a dedicated service account, and follows a predictable pattern. The scenario describes rapid connections to several servers with the same domain user account, which is not typical of backup operations. Additionally, backup traffic is usually baselined, so a sudden burst from a single user account would be anomalous and warrant investigation.
- ✗
A vulnerability scanner enumerating SMB services
Why it's wrong here
A vulnerability scanner would connect to port 445 on many hosts, but it typically does not authenticate with a domain user account in the way described. Scanners often use null sessions or dedicated scan credentials, and their activity is usually scheduled and authorized. The use of the same domain user account across multiple servers in minutes points to credential-based lateral movement rather than scanning.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.