200-201 exam dumps

200-201 practice question 274 of 405

Cisco Cybersecurity Associate. Associate level, Cisco. Free question with the correct answer and a full explanation.

200-201 Question 274

Single answer

A security analyst is investigating unusual network traffic patterns within an organization. They identify multiple devices communicating over port 443, but the payloads of the packets do not appear to be encrypted. Which protocol is MOST likely being misused in this scenario?

  1. A

    HTTP

  2. B

    HTTPS

  3. C

    FTP

  4. D

    DNS

Show answer and explanation

Correct answer: B

Explanation

Port 443 is commonly associated with HTTPS, which uses SSL/TLS to encrypt communication. If traffic over port 443 is not encrypted, it indicates that HTTPS may be misused or improperly configured, potentially exposing the organization to security risks. This scenario highlights the importance of understanding protocol behavior and ensuring proper implementation to maintain security.

  • A. Incorrect.

    HTTP is typically used over port 80 and does not provide encryption. In this case, the traffic is occurring over port 443, which is commonly used for encrypted protocols, making HTTP an unlikely candidate.

  • B. Correct.

    HTTPS is expected to encrypt communication using SSL/TLS over port 443. If payloads are not encrypted despite using port 443, it suggests that HTTPS is being misused or not properly implemented.

  • C. Incorrect.

    FTP usually operates over ports 20 and 21, not port 443. Therefore, it is unlikely to be the protocol in question here.

  • D. Incorrect.

    DNS typically operates over UDP port 53 (or sometimes TCP for larger queries) and is unrelated to port 443, making it an unlikely candidate.

Timed practice exam

Take a 200-201 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam