nerdexam
Cisco

200-201 · Question #160

Refer to the exhibit. An engineer received a ticket to analyze unusual network traffic. What is occurring?

The correct answer is C. denial-of-service attack. Assuming the exhibit showed characteristics of a DoS attack, the observed network traffic indicates a denial-of-service attack, characterized by an overwhelming volume of requests or malformed packets aimed at exhausting target resources or bandwidth.

Submitted by valeria.br· Mar 6, 2026Network Intrusion Analysis

Question

Refer to the exhibit. An engineer received a ticket to analyze unusual network traffic. What is occurring?

Exhibit

200-201 question #160 exhibit

Options

  • Adata exfiltration
  • Bregular network traffic; no suspicious activity
  • Cdenial-of-service attack
  • Dcookie poisoning

How the community answered

(43 responses)
  • A
    7% (3)
  • B
    16% (7)
  • C
    72% (31)
  • D
    5% (2)

Why each option

Assuming the exhibit showed characteristics of a DoS attack, the observed network traffic indicates a denial-of-service attack, characterized by an overwhelming volume of requests or malformed packets aimed at exhausting target resources or bandwidth.

Adata exfiltration

Data exfiltration involves unauthorized data transfer out of an organization, which would typically show large outbound data flows, not necessarily a flood of incoming requests designed to disrupt.

Bregular network traffic; no suspicious activity

'Regular network traffic' would not generate a ticket for 'unusual network traffic' and generally would not exhibit characteristics of overwhelming or disruptive patterns.

Cdenial-of-service attackCorrect

Assuming the exhibit showed large volumes of requests/packets, often malformed or incomplete, from multiple sources targeting specific services or the network itself, a denial-of-service (DoS) attack aims to disrupt or make a service unavailable by overwhelming the target system with a flood of traffic or requests, consuming its resources, or exploiting vulnerabilities to cause it to crash.

Dcookie poisoning

Cookie poisoning involves modifying HTTP cookies to gain unauthorized access or manipulate application behavior, which is an application-layer attack and would not typically manifest as the broad network traffic patterns indicative of a DoS attack.

Concept tested: Network traffic analysis for DoS attacks

Source: https://learn.microsoft.com/en-us/azure/ddos-protection/ddos-attack-overview

Topics

#network traffic analysis#DoS attack#traffic patterns

Community Discussion

No community discussion yet for this question.

Full 200-201 Practice