Courseiva
Network Security →easyMultiple Choice

ISC2 CC Network Security Practice Question

A security analyst notices unusual traffic from an internal workstation to an external IP address on port 25. Which protocol is most likely being used?

⚠ Common exam trap

CC often tests port number memorization; candidates may confuse port 25 with other common ports like 21 (FTP), 53 (DNS), or 80 (HTTP).

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

SMTP

SMTP (Simple Mail Transfer Protocol) operates over TCP port 25 by default for relaying and receiving email. Unusual outbound traffic on port 25 from an internal workstation often indicates a compromised host sending spam or a malware infection attempting to exfiltrate data via email. The other protocols listed use different default ports: FTP uses 20/21, DNS uses 53, and HTTP uses 80.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    SMTP

    Why this is correct

    Port 25 is the standard TCP port for SMTP, used for sending and relaying email. Outbound traffic from an internal workstation to an external address on this port suggests the host is acting as a mail client or, more likely in this scenario, a compromised machine sending spam.

  • ✗

    FTP

    Why it's wrong here

    Port 25 carries SMTP, so FTP cannot explain this traffic; FTP uses ports 20 and 21 for data and control channels. FTP is tempting because it also moves data to external hosts, and it would be the answer had the capture shown port 21 commands or port 20 transfers.

  • ✗

    DNS

    Why it's wrong here

    DNS resolves names to IP addresses over port 53, so it cannot account for traffic on port 25. It is tempting because DNS queries also leave the internal network for external addresses, and DNS tunnelling can hide exfiltration, but that traffic still uses port 53 unless deliberately reconfigured.

  • ✗

    HTTP

    Why it's wrong here

    Port 25 carries SMTP, so HTTP traffic would not appear there; HTTP uses TCP 80 or 443. HTTP is tempting because it dominates network traffic and is frequently abused for command-and-control and data exfiltration, making it the right answer when unusual traffic targets web ports rather than mail submission.

About these practice questions

Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.