200-201 Security Monitoring Practice Question
A security analyst is reviewing a packet capture in Wireshark and notices a series of DNS queries for randomly generated domain names such as 'a1b2c3d4e5.com', 'f6g7h8i9j0.net', and 'k1l2m3n4o5.org'. The queries are sent to multiple different DNS servers. Which type of malicious activity does this pattern most likely indicate?
⚠ Common exam trap
Candidates often confuse DGA with DNS tunneling; DGA generates many random domains, while tunneling encodes data within queries to a single domain.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Domain Generation Algorithm (DGA) used by malware for C2.
The pattern of numerous DNS queries for random-looking domain names across different TLDs is characteristic of a Domain Generation Algorithm (DGA). Malware uses DGAs to generate many potential C2 domains, making it difficult for defenders to block them all. The analyst should investigate the host making these queries for signs of infection. Other options like DNS tunneling, cache poisoning, or fast flux do not match the observed pattern of multiple random domains.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
DNS tunneling for data exfiltration.
Why it's wrong here
DNS tunneling typically involves encoding data within DNS queries and responses to a single controlled domain, often with long subdomains or TXT records. The pattern here shows multiple random domains and multiple DNS servers, which is more characteristic of domain generation algorithms (DGAs) used by malware for command and control. Tunneling would usually target one domain consistently, not many random ones.
- ✓
Domain Generation Algorithm (DGA) used by malware for C2.
Why this is correct
DGAs are used by malware to generate a large number of pseudo-random domain names that it can query to find its command and control server. The pattern of many random-looking domains, often with different top-level domains, and queries to various DNS servers, is a classic indicator of DGA activity. This allows the malware to evade domain blacklisting. The analyst should correlate with endpoint logs to identify the infected host.
- ✗
Fast flux DNS technique.
Why it's wrong here
Fast flux involves rapidly changing the IP addresses associated with a single domain name to evade takedowns. It does not involve generating many random domain names. The observed pattern is multiple distinct domains, not multiple IPs for one domain. While fast flux is used in malicious networks, the scenario describes DGA behavior more directly.
- ✗
DNS cache poisoning attack.
Why it's wrong here
DNS cache poisoning involves injecting false DNS records into a resolver's cache to redirect legitimate traffic to malicious IPs. It typically involves spoofed responses to a specific query, not a high volume of random domain queries from a single host. The pattern described is outbound queries, not the poisoning itself. Therefore, this is not the most likely activity.
Go deeper
Related to this question
About these practice questions
One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.