Courseiva
mediumMultiple Select

200-201 Practice Question: Which THREE indicators are commonly found in…

Which THREE indicators are commonly found in network traffic that suggest a host is part of a botnet? (Choose three.)

⚠ Common exam trap

Cisco often tests the distinction between normal network behavior (like large downloads or frequent DNS queries) and specific botnet indicators (IRC on non-standard ports, connections to low-reputation IPs, and asymmetric outbound traffic patterns), trapping candidates who confuse generic high-bandwidth activity with botnet C2 signatures.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Connections to known IRC servers on non-standard ports

Option A is correct because botnets historically use IRC command-and-control (C2) channels, often on non-standard ports like 6667 or 31337 to evade basic filtering, so connections to known IRC servers on such ports are a classic botnet indicator. Option C is correct because bots periodically beacon to C2 infrastructure, and repeated connections to IP addresses with poor reputation (e.g., known malicious hosts, low-reputation ASNs) strongly suggest compromised hosts checking in. Option D is correct because botnets frequently conduct distributed activities such as spam, DDoS, or scanning, producing high volumes of outbound traffic to many destinations, which is anomalous for a normal host. Option B is not a typical botnet indicator because large file downloads from external servers more often indicate legitimate patching, software distribution, or user activity rather than bot behavior. Option E is not a botnet indicator because frequent DNS queries to legitimate corporate DNS servers are normal in enterprise environments and do not by themselves suggest compromise.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Connections to known IRC servers on non-standard ports

    Why this is correct

    IRC remains a common botnet C2 channel; compromised hosts beacon to IRC servers on non-standard ports to evade simple filtering. This satisfies the stem's traffic-indicator requirement, since such connections reveal command-and-control rendezvous rather than legitimate user activity.

  • ✗

    Large file downloads from external servers

    Why it's wrong here

    Large downloads from external servers indicate data exfiltration or normal patching, not botnet membership; botnet hosts typically show beaconing, IRC or HTTP C2 callbacks, and DNS queries to known malicious domains. It is tempting because volume anomalies suggest compromise, but the question asks for botnet indicators specifically.

  • ✓

    Periodic connections to IP addresses with poor reputation

    Why this is correct

    Beaconing to low-reputation IPs reflects botnet C2 infrastructure, which is frequently blacklisted after prior malicious use. Periodic contact with such addresses satisfies the stem's network-traffic indicator criterion, distinguishing automated check-ins from normal browsing to reputable destinations.

  • ✓

    High volumes of outbound traffic to multiple destinations

    Why this is correct

    Bots often conduct spam, DDoS or scanning, producing large outbound volumes spread across many destinations. This traffic pattern satisfies the stem's indicator requirement because the fan-out and volume exceed typical workstation behaviour, revealing coordinated botnet activity.

  • ✗

    Frequent DNS queries to legitimate corporate DNS servers

    Why it's wrong here

    Botnet beaconing typically resolves algorithmically generated domains or contacts command-and-control infrastructure, not routine corporate resolvers. Frequent queries to legitimate internal DNS servers reflect normal name resolution, so this indicator is absent. It would be relevant when hunting for DNS tunnelling or exfiltration through internal resolvers.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.