Courseiva
Security MonitoringeasyMultiple ChoiceObjective-mapped

200-201 Security Monitoring Practice Question

A security analyst is reviewing network traffic and notices a high volume of small packets from an internal IP to a single external IP on port 53. Which type of activity is most likely indicated?

⚠ Common exam trap

Cisco often tests the distinction between a DNS amplification attack (which uses large responses to flood a victim) and DNS tunneling (which uses small, consistent queries for covert data transfer), so candidates may confuse the two due to both involving DNS traffic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Data exfiltration via DNS tunneling

DNS tunneling encodes data within DNS queries and responses, often using small packets to evade detection. A high volume of small packets from an internal IP to a single external IP on port 53, without corresponding internal DNS server traffic, is a classic indicator of data exfiltration via DNS tunneling.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • DNS amplification attack

    Why it's wrong here

    DNS amplification attacks send small queries that generate large responses, but the source packets are small; the high volume of small packets from the internal host suggests outbound data exfiltration.

  • Port scan

    Why it's wrong here

    Port scans target multiple ports, not a single port with many packets.

  • Data exfiltration via DNS tunneling

    Why this is correct

    DNS tunneling encodes data in DNS queries to exfiltrate data, often resulting in many small packets to a single external DNS server.

  • Normal DNS resolution

    Why it's wrong here

    Normal DNS traffic typically involves queries to various servers, not a high volume to a single IP.

About these practice questions

Courseiva writes every 200-201 question from scratch — 979 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.