200-201 exam dumps

200-201 practice question 273 of 405

Cisco Cybersecurity Associate. Associate level, Cisco. Free question with the correct answer and a full explanation.

200-201 Question 273

Single answer

A security analyst is investigating unusual traffic patterns within the network and observes that a large number of packets are being sent to port 53. Which protocol is most likely being used for this activity?

  1. A

    HTTP

  2. B

    DNS

  3. C

    FTP

  4. D

    SMTP

Show answer and explanation

Correct answer: B

Explanation

Port 53 is the default port for DNS traffic, which is used for resolving domain names to IP addresses. The large number of packets directed to this port suggests DNS activity, potentially legitimate or abusive, such as DNS tunneling or amplification attacks. Understanding the purpose of protocols and their associated ports is critical for identifying unusual or malicious network behavior.

  • A. Incorrect.

    HTTP is used for web traffic over ports such as 80 or 443, not port 53.

  • B. Correct.

    DNS (Domain Name System) commonly operates on port 53 and is responsible for translating domain names into IP addresses. This aligns with the observed traffic patterns.

  • C. Incorrect.

    FTP (File Transfer Protocol) typically uses ports 20 and 21 for transferring files, not port 53.

  • D. Incorrect.

    SMTP (Simple Mail Transfer Protocol) is used for email communication and usually operates on ports 25, 587, or 465, not port 53.

Timed practice exam

Take a 200-201 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam