Courseiva
mediumMultiple SelectObjective-mapped

200-201 Practice Question: Which THREE indicators are commonly found in…

Which THREE indicators are commonly found in network traffic that suggest a host is part of a botnet? (Choose three.)

⚠ Common exam trap

Cisco often tests the distinction between normal network behavior (like large downloads or frequent DNS queries) and specific botnet indicators (IRC on non-standard ports, connections to low-reputation IPs, and asymmetric outbound traffic patterns), trapping candidates who confuse generic high-bandwidth activity with botnet C2 signatures.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Connections to known IRC servers on non-standard ports

Botnets often use IRC (Internet Relay Chat) for command and control (C2) communication. Attackers configure IRC servers on non-standard ports (e.g., TCP 6667–6669 are common, but botnets may use ports like 8080, 8443, or random high ports) to evade detection by security tools that monitor default IRC ports. The presence of persistent IRC connections to unusual ports is a strong indicator of botnet activity.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Connections to known IRC servers on non-standard ports

    Why this is correct

    IRC is a common C2 channel.

  • Large file downloads from external servers

    Why it's wrong here

    Downloads are typically not a botnet indicator.

  • Periodic connections to IP addresses with poor reputation

    Why this is correct

    Botnets often beacon to malicious IPs.

  • High volumes of outbound traffic to multiple destinations

    Why this is correct

    Botnets often send stolen data or participate in DDoS.

  • Frequent DNS queries to legitimate corporate DNS servers

    Why it's wrong here

    This is normal traffic.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

Courseiva writes every 200-201 question from scratch — 979 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.