200-201 Security Monitoring Practice Question
During packet analysis in Wireshark, which THREE findings are indicators of potential malicious activity? (Choose THREE.)
⚠ Common exam trap
Cisco often tests the distinction between normal traffic patterns and protocol anomalies; the trap here is that candidates may overlook the 'unusually large' qualifier and dismiss ICMP anomalies as benign, or mistake a legitimate HTTPS connection for suspicious activity due to encryption.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
An unusually large ICMP echo request packet (e.g., 65,000 bytes).
Option B is correct because an ICMP echo request of roughly 65,000 bytes is abnormally large for a standard ping (normally 32–64 bytes of payload), indicating possible ICMP tunneling, data exfiltration, or a Ping of Death-style attack. Option C is correct because credentials transmitted in cleartext over HTTP can be captured by anyone sniffing the traffic, which is a clear sign of insecure and potentially malicious credential harvesting or a policy violation. Option E is correct because a flood of TCP SYN packets to multiple ports on a single host is the classic signature of a port scan (e.g., SYN scan), often a precursor to exploitation. Option A is not an indicator because HTTPS to a well-known website is normal, expected, encrypted traffic. Option D is not an indicator because a routine DNS query for a common domain is ordinary network behavior and not inherently suspicious.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
An HTTPS connection to a well-known website.
Why it's wrong here
Encrypted traffic to a legitimate, well-known site matches expected user behaviour, so it provides no anomaly to flag. Analysts find it tempting because HTTPS inspection reveals malicious payloads hidden in TLS, but that requires decryption and a suspicious destination or certificate, neither present here.
- ✓
An unusually large ICMP echo request packet (e.g., 65,000 bytes).
Why this is correct
Oversized ICMP echo requests exploit the protocol's normal 64-byte payload ceiling, indicating tunnelling or data exfiltration hidden inside ping traffic. This satisfies the stem's malicious-activity criterion because legitimate diagnostics never require 65,000-byte payloads, and such frames often signal covert channels or ping floods.
- ✓
Unencrypted credentials in an HTTP packet.
Why this is correct
Unencrypted credentials in an HTTP packet expose authentication data to any network observer, directly indicating credential interception or poor security practise. Unlike HTTPS, HTTP transmits plaintext, so captured usernames and passwords confirm sensitive data exposure, satisfying the malicious-activity indicator criterion in the stem.
- ✗
A normal DNS query for a common domain.
Why it's wrong here
A routine lookup for a popular domain resolves normally and shows no tunnelling, DGA pattern or oversized TXT record, so it is benign. It is tempting because DNS is abused for command-and-control and exfiltration, yet those cases involve anomalous query volume, entropy or unfamiliar domains, not common ones.
- ✓
A large number of TCP SYN packets to various ports on one host.
Why this is correct
Numerous SYN packets hitting many ports on one host indicate a port scan, as the attacker probes for open services. The high volume of half-open connection attempts to varied ports distinguishes scanning from normal client behaviour.
Visual reference
Go deeper
Related to this question
About these practice questions
This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.