hardMultiple Choice
200-201 Practice Question: Which type of traffic is most prominent in this…
Exhibit
Refer to the exhibit. SrcAddr DstAddr SrcPort DstPort Proto Packets Bytes 10.0.0.1 10.0.0.2 12345 80 TCP 100 5000 10.0.0.1 10.0.0.3 54321 22 TCP 50 3000
Which type of traffic is most prominent in this NetFlow data?
⚠ Common exam trap
Cisco often tests the ability to distinguish between HTTP and HTTPS by port number, and the trap here is that candidates might assume HTTPS is more common due to modern encryption trends, but the NetFlow data explicitly shows higher traffic on port 80.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
HTTP
HTTP traffic is most prominent because the NetFlow data shows a high volume of packets and bytes on TCP port 80, which is the default port for HTTP. NetFlow records summarize traffic flows, and the large number of flows and bytes on port 80 indicates that HTTP is the dominant protocol in the captured data.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
SSH
Why it's wrong here
SSH carries interactive terminal sessions, so its byte and packet counts stay tiny relative to bulk transfers; it cannot dominate a NetFlow summary unless the capture is filtered to port 22. It is tempting because SSH is common on managed network devices, and identifying it would be the goal if the question asked which traffic is encrypted or administrative.
- ✓
HTTP
Why this is correct
HTTP dominates the NetFlow records, evidenced by the highest volume of flows to web service ports 80 and 443. This traffic profile identifies web browsing as the most prominent activity, satisfying the stem's requirement to name the leading protocol.
- ✗
DNS
Why it's wrong here
DNS typically generates many short flows but tiny byte volumes, so it rarely dominates NetFlow records ranked by bytes or packets. It is tempting because DNS queries are numerous and visually conspicuous in flow lists, yet the prominent traffic is determined by volume, not query count.
- ✗
HTTPS
Why it's wrong here
HTTPS flows are usually fewer but far larger, carrying bulk data transfers and web sessions; prominence in NetFlow depends on byte and packet counts, not flow quantity. It is tempting because encrypted web traffic is ubiquitous, but DNS or other high-frequency protocols can outnumber it in flow records.
About these practice questions
Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.