easyMultiple Select
200-201 Practice Question: Which TWO types of network traffic should be…
Which TWO types of network traffic should be analyzed to detect a data exfiltration attempt via HTTP? (Choose two.)
⚠ Common exam trap
Cisco often tests the distinction between layers of the OSI model, trapping candidates who confuse transport-layer handshakes (TCP) or network-layer diagnostics (ICMP) with application-layer HTTP traffic analysis.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
HTTP request headers
HTTP request headers (B) are correct because exfiltration over HTTP often hides data in custom, non-standard, or unusually long header fields (e.g., Cookie, User-Agent, Referer, X-* headers), and inspecting them reveals anomalous values, oversized fields, or encoded payloads that indicate data being smuggled out. HTTP request body (C) is correct because the body is the primary carrier for exfiltrated content in POST/PUT requests, so examining it for large volumes, base64/hex-encoded blobs, or sensitive data patterns is essential to detect the theft. ICMP echo requests (A) are not HTTP traffic and are typically used for reachability testing or covert channels via ping payloads, not HTTP exfiltration. DNS query responses (D) relate to DNS tunneling/exfiltration, a separate protocol channel, not HTTP. The TCP three-way handshake (E) only establishes the connection (SYN, SYN-ACK, ACK) and carries no application-layer payload, so it cannot reveal exfiltrated data.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
ICMP echo requests
Why it's wrong here
ICMP echo requests are diagnostic reachability probes carrying no application payload, so they cannot expose data leaving over HTTP. It is tempting because tunnelled ICMP can exfiltrate data, but that is a separate channel; HTTP exfiltration requires inspecting request methods, URIs and POST bodies.
- ✓
HTTP request headers
Why this is correct
HTTP request headers can carry exfiltrated data hidden in custom fields, cookies or user-agent strings, and unusual header sizes or values reveal tunnelling. Analysing them detects covert channels that body inspection alone would miss, satisfying the requirement to identify HTTP-based exfiltration.
- ✓
HTTP request body
Why this is correct
The HTTP request body carries the bulk payload, so large or encoded POST bodies to unusual destinations indicate data being smuggled out. Inspecting body content and size exposes exfiltration that headers alone cannot reveal, satisfying the requirement to detect HTTP-based data theft.
- ✗
DNS query responses
Why it's wrong here
DNS query responses reveal domain lookups, not the HTTP payload carrying exfiltrated data; exfiltration over HTTP appears in request bodies, headers and URLs. DNS monitoring is the right choice when detecting tunnelling or beaconing via DNS itself, where encoded data hides in query names or TXT records.
- ✗
TCP three-way handshake
Why it's wrong here
The three-way handshake only establishes a TCP connection; it carries no payload, so it cannot reveal stolen data. It is tempting because connection metadata helps spot unusual destinations, but exfiltration detection needs HTTP request bodies, headers and upload sizes, not session setup packets.
Visual reference
Go deeper
Related to this question
About these practice questions
This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.