Courseiva

200-201 Network Intrusion Analysis Practice Question

A junior analyst is asked to identify which log source would best confirm that an internal workstation attempted to resolve a suspicious domain shortly before an alert fired. The environment forwards DNS query logs from its recursive resolvers to the SIEM. Which action should the analyst take first?

⚠ Common exam trap

The trap here is pivoting to firewall or reverse-lookup data first, when the DNS query log is the only source that directly records the name the host asked to resolve.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Query the forwarded DNS logs for the workstation's IP and the suspicious domain name.

When recursive resolver query logs are already centralized in the SIEM, searching them for the workstation's IP and the suspicious domain is the fastest authoritative way to confirm the lookup and its timestamp. Firewall logs show IP connections rather than names, reverse lookups describe the workstation itself, and the hosts file only covers static overrides, so none of those directly answer whether the domain was resolved.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Run a reverse DNS lookup on the workstation's IP address to see its registered name.

    Why it's wrong here

    Reverse DNS resolves an IP address back to a hostname for the workstation itself; it says nothing about which domains that workstation queried. It cannot confirm contact with the suspicious domain and may return stale or missing PTR records. This action consumes time without answering the investigative question about the workstation's outbound name resolution.

  • ✓

    Query the forwarded DNS logs for the workstation's IP and the suspicious domain name.

    Why this is correct

    Because recursive resolver query logs are already forwarded to the SIEM, searching for the workstation's source IP paired with the suspicious domain directly confirms whether the host issued that lookup and when. This is the most direct and authoritative evidence of resolution attempts. It also establishes a timeline anchor that the analyst can use to pivot to proxy, firewall, and endpoint data for corroboration.

  • ✗

    Inspect the workstation's local hosts file for static entries mapping the suspicious domain.

    Why it's wrong here

    The hosts file only reveals static local overrides and would not show dynamic queries sent to the recursive resolver. A malicious domain would rarely be pre-mapped there, and absence of an entry does not prove no lookup occurred. It is a useful secondary check for redirection, but it cannot confirm the query activity the analyst needs to verify.

  • ✗

    Search the firewall session logs for outbound connections to the suspicious domain's IP address.

    Why it's wrong here

    Firewall session logs show connections to IP addresses, not domain names, and they cannot directly show which name the workstation tried to resolve. They are useful for confirming whether a connection followed the lookup, but they do not answer the resolution question. The analyst should first establish the DNS query itself, then pivot to firewall logs to see if the resolved address was contacted.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.