Courseiva

200-201 · topic practice

Network Intrusion Analysis practice questions

This domain covers reading packets and logs to spot malicious activity: using tools like Wireshark and tcpdump to pull files from PCAPs, recognizing exfiltration and command-and-control patterns in DNS, FTP, and HTTP traffic, and mapping observed behavior to the Cyber Kill Chain. Questions give you a traffic scenario and ask for the correct interpretation or tool.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Network Intrusion Analysis

What the exam tests

What to know about Network Intrusion Analysis

Be able to open a PCAP, extract transferred files, and classify traffic as normal or malicious. The most important skill is distinguishing exfiltration from command-and-control and naming the correct Cyber Kill Chain phase for the evidence.

Extracting transferred files from a PCAP using Wireshark's export objects or tcpdump

Identifying data exfiltration over FTP, HTTP, or DNS by volume, direction, and timing

Recognizing DNS tunneling via high-entropy or base64-encoded subdomain labels

Mapping observed network activity to the correct Cyber Kill Chain phase

Watch out for

Common Network Intrusion Analysis exam traps

  • ▸Assuming any large transfer is exfiltration; direction, timing, and source host role determine whether it is malicious.
  • ▸Confusing DNS tunneling with normal CDN or load-balancer subdomains; look for encoded or high-entropy labels, not just many queries.
  • ▸Picking the wrong Kill Chain phase: exfiltration is data leaving, while command-and-control is beaconing or instructions.

Practice set

Network Intrusion Analysis questions

20 questions · select your answer, then reveal the explanation

During an incident response, an analyst extracts a file from a PCAP using Wireshark's 'Export Objects' feature. The file contains shellcode that uses NOP sleds and encodes a reverse shell command. Which Cyber Kill Chain phase does this file represent?

A network analyst is examining a PCAP file and applies the Wireshark display filter 'http.request'. The results show several POST requests to '/login.php' with parameters containing 'username=admin&password=secret'. What type of attack is indicated?

Question 3mediummulti select
Read the full DNS explanation →

A security analyst is investigating a suspected data exfiltration incident. Which TWO of the following indicators are most consistent with exfiltration over DNS?

An analyst is analyzing a PCAP from a compromised host. Which THREE of the following are common indicators of exploitation attempts in network traffic?

An analyst captures traffic and sees a TCP connection with only a SYN packet and an RST response. No SYN-ACK is observed. Which scan technique is this?

An analyst identifies an alert for 'ET TROJAN Win32/DarkComet RAT Beacon'. The analyst confirms the host is infected. Which THREE phases of the Cyber Kill Chain have been completed prior to this C2 beacon? (Choose three.)

A SOC analyst is investigating a suspected data exfiltration. Which THREE indicators in network traffic are most consistent with exfiltration? (Choose three.)

An analyst reviews a PCAP and sees HTTP requests containing script tags and event handlers such as 'onload' and 'onerror'. Additionally, the URI contains 'alert(1)'. Which TWO types of attacks are indicated? (Select 2)

In Wireshark, which filter can be used to quickly find all HTTP requests that contain a specific keyword in the URL?

Which MITRE ATT&CK tactic corresponds to the Cyber Kill Chain phase 'Actions on Objectives'?

A security analyst is investigating a PCAP that shows multiple failed SMB authentication attempts from a single host to different IP addresses, followed by a successful authentication. Which TWO techniques are likely being used?

A PCAP contains the following patterns: (1) A TCP connection with a complete handshake to an external IP on port 443, (2) periodic data transfers every 60 seconds of approximately 1 KB, (3) the domain name in the TLS SNI field is generated by a DGA. Which THREE indicators are present?

An analyst identifies HTTP traffic containing the string "<script>alert('XSS')</script>" in the URL parameter. Which TWO attack types are likely being attempted?

An analyst observes repeated TCP SYN packets to various ports on a target IP with no SYN-ACK responses. What type of scan is most likely being performed?

During alert triage, an analyst determines that an alert was triggered by legitimate administrative activity. How should this alert be classified?

An analyst analyzing a PCAP sees a series of TCP connections where the client sends data with interactive patterns and receives commands. This is most likely indicative of:

Which TWO of the following are valid classifications for alerts during triage?

An analyst is triaging alerts and encounters a scenario where an IDS alerted on a network scan, but further investigation reveals the traffic was from a legitimate vulnerability scanner. Which TWO terms best describe this alert?

An analyst observes a host making outbound connections to a server on TCP port 443, with traffic patterns showing small packets at regular 60-second intervals. The destination IP is in a country where the company does no business. Which THREE characteristics suggest this is C2 beaconing?

An analyst is examining a PCAP for signs of pass-the-hash attack. Which THREE indicators would be consistent with pass-the-hash?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Network Intrusion Analysis sessions

Start a Network Intrusion Analysis only practice session

Every question in these sessions is drawn from the Network Intrusion Analysis domain — nothing else.

Related practice questions

Related 200-201 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the 200-201 exam test about Network Intrusion Analysis?
Be able to open a PCAP, extract transferred files, and classify traffic as normal or malicious. The most important skill is distinguishing exfiltration from command-and-control and naming the correct Cyber Kill Chain phase for the evidence.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Network Intrusion Analysis questions in a focused session?
Yes — the session launcher on this page draws every question from the Network Intrusion Analysis domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other 200-201 topics?
Use the topic links above to move to related areas, or go back to the 200-201 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the 200-201 exam covers. They are not copied from any real exam or dump site.