mediumMultiple ChoiceObjective-mapped
200-201 Practice Question: A security analyst is investigating an alert that…
A security analyst is investigating an alert that indicates a host is sending a large number of DNS queries to an external domain. The analyst wants to determine if the traffic is malicious and if it is using a DNS tunnel. Which type of analysis should the analyst perform to confirm the presence of a DNS tunnel?
⚠ Common exam trap
Cisco often tests the distinction between detecting a general anomaly (e.g., high traffic volume) and confirming a specific technique (e.g., DNS tunneling), where candidates mistakenly choose a broad indicator like traffic volume (Option B) instead of the packet-level analysis that directly reveals the tunneling mechanism.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Analyze the payload size and query frequency of the DNS packets to detect anomalous patterns.
DNS tunneling typically involves encoding data within DNS queries or responses, resulting in abnormally large payload sizes and unusual query frequencies. By analyzing these specific packet attributes, an analyst can detect the anomalous patterns characteristic of a DNS tunnel, such as high query rates to a single domain or payloads exceeding standard DNS message sizes (e.g., >512 bytes for UDP). This direct inspection of DNS packet content is the most reliable method to confirm tunneling activity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Analyze the payload size and query frequency of the DNS packets to detect anomalous patterns.
Why this is correct
DNS tunneling typically uses large payloads and unusual query patterns.
- ✗
Check the volume of DNS traffic from the host to identify any increase over baseline.
Why it's wrong here
Increased volume alone is not definitive; it could be legitimate.
- ✗
Examine the source IP addresses of the DNS queries to see if they originate from multiple hosts.
Why it's wrong here
Source IP addresses can be spoofed or changed.
- ✗
Review the firewall logs to identify any blocked DNS queries to the external domain.
Why it's wrong here
Firewall logs may not show the payload details needed to confirm tunneling.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 979 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.