200-201 exam dumps

200-201 practice question 236 of 405

Cisco Cybersecurity Associate. Associate level, Cisco. Free question with the correct answer and a full explanation.

200-201 Question 236

Single answer

You are a cybersecurity analyst reviewing proxy logs to investigate a potential data exfiltration event. The logs reveal multiple HTTP requests to an unfamiliar external domain from a single internal workstation. These requests include unusually large amounts of data being sent via POST requests. What is the most likely reason for this activity?

  1. A

    The internal workstation is infected with malware that is exfiltrating sensitive data to an attacker-controlled domain.

  2. B

    The internal workstation is running a legitimate software update process, which requires sending large data packets to an external server.

  3. C

    The external domain is hosting a phishing website, and the logs indicate a user interacting with the site.

  4. D

    The internal workstation is acting as a proxy server for other devices within the network, which is why it is sending large amounts of data.

Show answer and explanation

Correct answer: A

Explanation

Proxy logs are an essential tool for identifying suspicious activity within a network. In this scenario, the combination of POST requests with large data transfers to an unfamiliar domain strongly suggests data exfiltration by malware. Legitimate processes like software updates would communicate with known domains, and phishing websites are more likely to involve user input rather than large outbound data transfers. This makes the first option the most plausible choice.

  • A. Correct.

    This is the most likely explanation based on the context provided. Unfamiliar domains combined with large POST requests often indicate malicious activity, particularly data exfiltration.

  • B. Incorrect.

    While legitimate software updates can involve large data transfers, they typically communicate with well-known and trusted domains, not unfamiliar ones.

  • C. Incorrect.

    A phishing website typically involves receiving data from the user (e.g., login credentials) rather than the user sending large amounts of data to the site.

  • D. Incorrect.

    If the workstation were acting as a proxy server, the logs would likely show traffic from multiple devices, not just a single workstation.

Timed practice exam

Take a 200-201 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam