Courseiva
mediumMultiple ChoiceObjective-mapped

200-201 Practice Question: A security analyst is investigating an alert that…

A security analyst is investigating an alert that indicates a host is sending a large number of DNS queries to an external domain. The analyst wants to determine if the traffic is malicious and if it is using a DNS tunnel. Which type of analysis should the analyst perform to confirm the presence of a DNS tunnel?

⚠ Common exam trap

Cisco often tests the distinction between detecting a general anomaly (e.g., high traffic volume) and confirming a specific technique (e.g., DNS tunneling), where candidates mistakenly choose a broad indicator like traffic volume (Option B) instead of the packet-level analysis that directly reveals the tunneling mechanism.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Analyze the payload size and query frequency of the DNS packets to detect anomalous patterns.

DNS tunneling typically involves encoding data within DNS queries or responses, resulting in abnormally large payload sizes and unusual query frequencies. By analyzing these specific packet attributes, an analyst can detect the anomalous patterns characteristic of a DNS tunnel, such as high query rates to a single domain or payloads exceeding standard DNS message sizes (e.g., >512 bytes for UDP). This direct inspection of DNS packet content is the most reliable method to confirm tunneling activity.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Analyze the payload size and query frequency of the DNS packets to detect anomalous patterns.

    Why this is correct

    DNS tunneling typically uses large payloads and unusual query patterns.

  • Check the volume of DNS traffic from the host to identify any increase over baseline.

    Why it's wrong here

    Increased volume alone is not definitive; it could be legitimate.

  • Examine the source IP addresses of the DNS queries to see if they originate from multiple hosts.

    Why it's wrong here

    Source IP addresses can be spoofed or changed.

  • Review the firewall logs to identify any blocked DNS queries to the external domain.

    Why it's wrong here

    Firewall logs may not show the payload details needed to confirm tunneling.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

One of 979 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.