Courseiva

200-201 Network Intrusion Analysis Practice Question

While reviewing firewall logs, an analyst notices repeated inbound connections from a single external IP to multiple internal hosts on TCP port 3389 within a short time window. Each connection lasts only a few seconds and is followed by a new connection to a different internal host. Which activity does this pattern most likely represent?

⚠ Common exam trap

The trap here is assuming any RDP traffic is administrative; scanning also touches port 3389 but with short, fan-out sessions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A vulnerability scan of internal RDP services

One external source rapidly opening short-lived TCP/3389 sessions to many internal hosts is characteristic of scanning for exposed RDP services. Legitimate RDP administration uses longer authenticated sessions from internal management addresses, backups use different protocols, and health checks come from internal load balancers at regular intervals. The burst of brief, fan-out connections therefore points to reconnaissance against RDP endpoints.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A load balancer health check against RDP servers

    Why it's wrong here

    Health checks originate from known load balancer addresses inside the environment and target a fixed server pool, not many separate hosts from one external IP. They also occur at regular intervals rather than a single burst. This option does not account for the external source or the one-to-many fan-out, so it does not fit the observed connection pattern.

  • ✓

    A vulnerability scan of internal RDP services

    Why this is correct

    Short-lived connections to TCP port 3389 across many internal hosts in rapid succession match a scan probing for reachable RDP services. Scanners often open and close sessions quickly to test responsiveness rather than complete authentication. The fan-out to multiple hosts from one external source reinforces scanning behavior, so this pattern indicates reconnaissance against RDP endpoints rather than any legitimate administrative session.

  • ✗

    An administrator using Remote Desktop to manage multiple servers

    Why it's wrong here

    Legitimate RDP administration typically involves longer sessions with full authentication and interactive use, not seconds-long connections that immediately move to a different host. An administrator would also usually connect from an internal management subnet rather than a single external IP. The rapid host-to-host progression and very short durations do not match normal administrative RDP usage, so this explanation is inconsistent with the logs.

  • ✗

    A backup application replicating data over RDP

    Why it's wrong here

    Backup replication does not use RDP on port 3389; it relies on SMB, NFS, or vendor-specific ports and maintains longer, high-throughput sessions. The brief connections observed here lack the sustained data transfer a backup job would produce. Attributing this to backup software misidentifies both the protocol and the traffic profile, leaving the fan-out scanning pattern unexplained.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.