Courseiva

200-201 Network Intrusion Analysis Practice Question

In a PCAP, an analyst sees an interactive shell session over TCP with irregular command prompts and responses. Which tool was likely used to generate this traffic?

⚠ Common exam trap

200-201 often tests the ability to distinguish between different types of network traffic, so candidates must recognize that an interactive shell session with command prompts is characteristic of a reverse shell, not a file transfer, port scan, or SQL injection.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Reverse shell payload

A reverse shell payload is the correct answer because it establishes an interactive shell session where the target machine connects back to the attacker's machine, allowing the attacker to execute commands. In a PCAP, this appears as a TCP session with irregular command prompts and responses, often with small packet sizes and interactive timing. The traffic may not follow standard protocol patterns, and the commands/responses are human-readable or encoded.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    File transfer tool

    Why it's wrong here

    File transfer tools move bulk data over FTP, SMB or similar, producing large sequential payloads rather than echoed command prompts and short responses. It is tempting because both use TCP sessions, but file transfer lacks the request-response shell semantics visible in the capture.

  • ✗

    Port scanner

    Why it's wrong here

    Port scanners probe many ports with SYN or connect attempts and capture open/closed states; they never establish a sustained bidirectional command-and-response dialogue. It is tempting because scanning traffic is TCP-heavy and irregular, but the correct choice is the tool that actually provides an interactive remote shell.

  • ✓

    Reverse shell payload

    Why this is correct

    A reverse shell payload initiates the TCP connection from the compromised host back to the attacker, then carries an interactive command session. The irregular prompts and responses in the PCAP reflect that outbound, attacker-controlled shell rather than a legitimate client-server protocol.

  • ✗

    SQL injection tool

    Why it's wrong here

    SQL injection tools send crafted query strings and receive database errors or result sets, not an interactive shell with prompts and command responses. It is tempting because both produce anomalous TCP payloads, but SQL injection targets a database parser rather than spawning a remote command session.

About these practice questions

Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.