hardMultiple Select
200-201 Practice Question: A security analyst discovers that an attacker…
A security analyst discovers that an attacker exfiltrated data using DNS tunneling. Which TWO controls should be implemented to detect or prevent this? (Select two.)
⚠ Common exam trap
Cisco often tests the misconception that DNSSEC or disabling recursion can stop DNS tunneling, but DNSSEC only signs records and does not inspect payloads, while disabling recursion breaks internal resolution without affecting external tunneling via forwarders.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Monitor DNS query sizes and frequencies
Option A is correct because DNS tunneling works by encoding stolen data into the subdomains and TXT/CNAME records of DNS queries, which produces abnormally long query names and unusually high query volumes or frequencies to a single domain; monitoring query size and rate via DNS logging or an IDS/IPS with DNS inspection detects these anomalies. Option B is correct because a DNS sinkhole redirects queries for known malicious or tunneling domains to a controlled non-routable address, breaking the attacker's command-and-control and exfiltration channel and logging the attempted lookups. Option C is not correct because disabling recursion on an internal resolver does not stop tunneling, which typically uses the resolver's normal recursive lookups to reach external authoritative servers. Option D is not correct because DNSSEC only provides origin authentication and integrity of DNS responses; it does not detect or block data hidden in query payloads. Option E is not correct because blocking all external DNS would break legitimate name resolution and is an impractical, overbroad control rather than a targeted tunneling defense.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Monitor DNS query sizes and frequencies
Why this is correct
DNS tunnelling hides stolen data inside query payloads, so unusually large or frequent queries to one domain expose it. Monitoring query size and frequency detects this anomaly at the resolver, satisfying the requirement to identify exfiltration without blocking legitimate DNS traffic.
- ✓
Use a DNS sinkhole
Why this is correct
A DNS sinkhole redirects queries for known malicious domains to a controlled non-routable address, severing the tunnelling channel before data leaves. This prevents exfiltration by denying the attacker's authoritative nameserver the queries it needs to receive encoded data.
- ✗
Disable recursive DNS on the internal DNS server
Why it's wrong here
Disabling recursion stops the internal server resolving external names, but DNS tunnelling typically abuses an already-authorised forwarder or resolver path, so exfiltration continues through permitted queries. Recursion control belongs in hardened authoritative-only deployments, such as blocking open resolvers to prevent cache-poisoning and amplification abuse, not in detecting tunnelled payloads.
- ✗
Implement DNSSEC
Why it's wrong here
DNSSEC provides origin authentication and integrity of DNS responses; it does not inspect query volume, payload entropy or record length, so tunnelled data passes validated. DNSSEC is correct for preventing cache poisoning and spoofing, not exfiltration.
- ✗
Block all DNS queries to external servers
Why it's wrong here
Blocking all external DNS halts legitimate resolution of internet services, an availability failure rather than a control. Egress filtering that permits only approved resolvers is the correct approach; a total block is never operationally viable.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.