Courseiva
Security Monitoring →mediumMultiple Select

200-201 Security Monitoring Practice Question

A security analyst is investigating a potential data exfiltration incident. Which TWO of the following are common indicators that data exfiltration may be occurring over DNS? (Choose two.)

⚠ Common exam trap

Cisco often tests the distinction between normal DNS behavior (e.g., CDN responses with many IPs) and anomalous patterns specific to tunneling, so candidates mistakenly pick A or E because they sound 'unusual' without understanding the underlying exfiltration mechanism.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

High volume of DNS queries to a single domain not normally visited

Option C is correct because DNS tunneling and exfiltration tools typically generate a high volume of queries to a single attacker-controlled domain that is not normally seen in the environment, as the malware encodes stolen data into the query names and needs many requests to move the data out. Option D is correct because DNS TXT records can carry arbitrary payloads, so unusually large TXT responses are a classic sign of data being returned or acknowledged over DNS, often used by tunneling utilities like iodine or dnscat2. Options A, B, and E are not valid indicators: multiple IP addresses in a response is normal for load balancing or round-robin DNS, AAAA queries from an IPv4-only network are common on dual-stack clients and OS resolvers, and high TTL values simply reflect caching policy and have no direct relationship to exfiltration.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    DNS responses with a large number of IP addresses

    Why it's wrong here

    Multiple IP addresses in a response are ordinary for load-balanced or round-robin records and reveal nothing about covert channels. This pattern is investigated when troubleshooting load-balancer health or DNS-based failover, where several A records are expected.

  • ✗

    DNS queries for AAAA records (IPv6) from an IPv4-only network

    Why it's wrong here

    AAAA queries are routine on dual-stack clients and IPv4-only hosts still emit them harmlessly, so volume and pattern matter, not record type. AAAA lookups become relevant when investigating IPv6 misconfiguration or dual-stack reconnaissance, not exfiltration specifically.

  • ✓

    High volume of DNS queries to a single domain not normally visited

    Why this is correct

    A high volume of DNS queries to one unusual domain signals tunnelling, where data is encoded into query names and smuggled out through the resolver. This satisfies the stem's DNS-based exfiltration indicator, since legitimate DNS traffic rarely concentrates on a single unfamiliar domain at volume.

  • ✓

    Unusually large DNS TXT record responses

    Why this is correct

    Oversized TXT responses provide the bandwidth DNS tunnelling needs, since TXT records carry arbitrary attacker-controlled payloads. Normal DNS queries return small answers, so abnormally large TXT replies satisfy the stem's exfiltration indicator by signalling covert data transfer through a protocol rarely inspected for volume anomalies.

  • ✗

    DNS query responses with high TTL values

    Why it's wrong here

    High TTL values are normal for stable records and actually reduce query frequency, which works against tunnelling, since exfiltration needs many repeated lookups. Long TTLs are examined when diagnosing stale DNS cache or slow failover, not data exfiltration.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.