200-201 Security Monitoring Practice Question
A Cisco Stealthwatch analyst notices a host on the internal network is sending periodic DNS queries to a single external domain with subdomains that are long, random-looking strings (e.g., a8f3k2j9d0x1.example.com). The queries occur every 60 seconds, and the responses are consistently NXDOMAIN. Which type of malicious activity does this pattern most strongly indicate?
⚠ Common exam trap
The trap here is assuming any DNS anomaly is tunneling, but tunneling requires bidirectional data transfer, while beaconing only needs periodic check-ins.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
DNS beaconing from a command-and-control implant
The combination of periodic timing, random subdomains, and consistent NXDOMAIN responses points to a DNS beacon from malware attempting to contact command-and-control. The implant uses DNS because it is often allowed through firewalls. The fixed interval and single destination domain distinguish this from normal DNS traffic or tunneling, which would carry larger payloads and expect responses.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
DNS tunneling for data exfiltration
Why it's wrong here
DNS tunneling typically involves larger, encoded payloads in queries and often returns successful responses carrying data. Here the queries are small, regular, and consistently fail with NXDOMAIN, which is not consistent with a tunnel that needs to receive data back. Tunneling would also show much higher query volume and varied record types to carry payloads.
- ✗
A misconfigured DNS resolver causing retry storms
Why it's wrong here
A misconfigured resolver would typically produce queries to many domains or repeated queries for the same name, not a steady stream of unique random subdomains under one domain. Retry storms also usually involve shorter intervals and multiple source ports, and they would not consistently target a single external domain with algorithmically generated labels.
- ✗
Normal DNS prefetching by a web browser
Why it's wrong here
Browser DNS prefetching resolves domains that the user is likely to visit, such as links on a page. It does not generate random-looking subdomains under a single external domain at fixed 60-second intervals. Prefetching also typically results in successful resolutions or cached entries, not persistent NXDOMAIN responses.
- ✓
DNS beaconing from a command-and-control implant
Why this is correct
The periodic, fixed-interval queries with random subdomains to one domain, combined with NXDOMAIN responses, are classic signs of a DNS beacon. The implant generates unique subdomains to check in and receives no response because the C2 domain may not be active yet or the analyst is seeing only the beacon attempts. This pattern is a well-known indicator of compromise.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.