Courseiva
hardMultiple Select

200-201 Practice Question: Which THREE of the following are common evasion…

Which THREE of the following are common evasion techniques used by attackers?

⚠ Common exam trap

Cisco often tests the distinction between evasion techniques and general security practices; the trap here is that candidates may mistake 'patching vulnerabilities' as an attacker action, when in reality it is a defender's mitigation strategy, not an evasion method.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Slow scans

Slow scans (A) are a common evasion technique because spreading probes over long intervals (e.g., nmap -T0/-T1 or --scan-delay) keeps the traffic below IDS/IPS thresholds and rate-based detection, making the reconnaissance blend into normal traffic. Fragmentation (B) evades detection by splitting packets into tiny fragments (e.g., fragroute or nmap -f) so that IDS/IPS devices cannot reassemble and match signatures against the full payload, while the target host reassembles them. Encryption (E) is a common evasion technique because attackers tunnel or encrypt command-and-control and exfiltration traffic (e.g., TLS, SSH, or custom crypto) so deep packet inspection cannot read payloads or match signatures. Using high ports (C) is not inherently an evasion technique since high ports are normal for legitimate services and are easily logged and detected. Patching vulnerabilities (D) is a defensive remediation action, the opposite of an attacker evasion technique.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Slow scans

    Why this is correct

    Slow scans spread probes over extended periods, keeping packet rates below threshold-based IDS and firewall detection windows. This low-and-slow timing evades signature and rate triggers, satisfying the evasion constraint by avoiding the volume spikes that perimeter monitoring relies on.

  • ✓

    Fragmentation

    Why this is correct

    Fragmentation splits malicious payloads across multiple packets, so signature-based intrusion detection systems reassemble traffic incorrectly or miss the attack entirely. This satisfies the stem's requirement for a common evasion technique, since attackers exploit inconsistent fragment handling to bypass network monitoring and filtering devices.

  • ✗

    Using high ports

    Why it's wrong here

    Using high ports is normal TCP/IP behaviour for client-side ephemeral connections, not an evasion technique; firewalls and monitoring still inspect that traffic. It is tempting because attackers sometimes bind services to unusual ports, but the correct evasion concepts involve protocol tunnelling, encryption or fragmentation that actually hide malicious activity from inspection.

  • ✗

    Patching vulnerabilities

    Why it's wrong here

    Patching vulnerabilities is a defensive remediation action that closes the weaknesses attackers exploit, so it cannot be an evasion technique. It is tempting because patching appears in security discussions alongside attacker activity, but it would be the correct answer to a question asking how defenders harden systems, not how attackers evade detection.

  • ✓

    Encryption

    Why this is correct

    Encryption conceals command-and-control payloads and exfiltrated data from deep packet inspection, letting malicious traffic blend with legitimate TLS sessions. Attackers also encrypt malware binaries or archives to evade signature and sandbox detection, since inspection tools cannot read the obfuscated content.

About these practice questions

One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.