Courseiva

200-201 Network Intrusion Analysis Practice Question

Which TWO of the following are typical indicators of a C2 beaconing communication?

⚠ Common exam trap

200-201 often tests whether candidates can distinguish C2 beaconing (small, periodic callbacks) from exfiltration (large outbound transfers) — the word 'outbound' in both options is the bait.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Regular intervals of communication at consistent times

Option A is correct because C2 beaconing is characterized by periodic check-ins from an infected host to its command-and-control server, producing highly regular, consistent communication intervals (often with jitter added to evade detection). Option E is correct because beaconing frequently abuses DNS for command-and-control or data exfiltration, generating queries to unusual, rarely visited, or algorithmically generated (DGA) domains that stand out against normal browsing patterns. Option B is not typical of beaconing itself, since beaconing traffic is usually small and low-volume; large outbound transfers suggest exfiltration rather than the beacon check-in. Option C describes a brute-force or password-guessing attack, not C2 beaconing. Option D describes ICMP echo requests (ping sweeps) used for host discovery or network reconnaissance, not command-and-control beaconing.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Regular intervals of communication at consistent times

    Why this is correct

    Beaconing malware contacts its command-and-control server on a fixed schedule, so traffic recurs at predictable intervals rather than randomly. This periodicity, often with consistent packet sizes, distinguishes automated beaconing from bursty human browsing and satisfies the stem's requirement for a typical C2 indicator.

  • ✗

    Large outbound data transfers to an external IP

    Why it's wrong here

    Bulk exfiltration to an external address describes data theft after compromise, whereas beaconing is characterised by small, regular check-in traffic at fixed intervals. It is tempting because both involve external IP contact, and would be correct when detecting large-scale data exfiltration rather than command-and-control heartbeat patterns.

  • ✗

    Multiple failed login attempts from a single source

    Why it's wrong here

    Repeated authentication failures indicate brute-force or password-spray attempts against a host, not the periodic, low-volume outbound callbacks a compromised host makes to its command-and-control server. It is tempting because failed logins are a genuine intrusion indicator, and would be correct when investigating credential attacks rather than beaconing.

  • ✗

    ICMP echo requests to multiple hosts

    Why it's wrong here

    ICMP echo requests to many hosts indicate network reconnaissance or host discovery scanning, not the repeated same-destination callbacks of beaconing. It is tempting because ICMP is sometimes tunnelled by malware, and would be correct when identifying ping sweeps or mapping live hosts on a subnet.

  • ✓

    DNS queries for domains that are rarely visited

    Why this is correct

    Rarely visited domains indicate beaconing because malware resolves its command-and-control infrastructure through DNS, often using algorithmically generated or low-reputation names that legitimate users never request. This satisfies the stem's requirement for a typical C2 indicator, as repeated queries to such domains reveal periodic callback behaviour.

About these practice questions

One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.