200-201 Security Concepts Practice Question
A security analyst is reviewing network traffic and observes a large number of DNS queries for randomly generated domain names, such as 'a1b2c3d4e5f6g7h8.com', from a single internal host. The queries are followed by responses with very short TTL values. The analyst suspects the host is compromised. Which type of malicious activity is most likely occurring?
⚠ Common exam trap
Many candidates confuse DGA with DNS tunneling or fast flux; DGA involves many random domains, while tunneling uses one domain with encoded data, and fast flux uses one domain with changing IPs.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Domain generation algorithm (DGA) used by malware for command-and-control (C2) communication
The high volume of unique, random-looking domain queries with short TTLs from a single host is a classic indicator of a domain generation algorithm. Malware uses DGA to periodically generate many domain names and attempt to resolve them, hoping to find the one registered by the attacker for command and control. This evades static domain blocklists and makes takedown difficult.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Fast flux DNS used to hide the location of a botnet controller
Why it's wrong here
Fast flux involves rapidly changing the IP addresses associated with a single domain name, often with short TTLs, to evade takedowns. Here, the host is querying many different random domain names, not repeatedly resolving one domain to changing IPs. The observed behavior is domain generation, not fast flux.
- ✗
DNS cache poisoning attack against the internal resolver
Why it's wrong here
DNS cache poisoning aims to insert false records into a resolver's cache, redirecting legitimate traffic. The scenario describes a single internal host making many random DNS queries, which is a client-side behavior, not an attack on the resolver itself. Poisoning would typically involve forged responses to the resolver, not a pattern of random queries from a host.
- ✓
Domain generation algorithm (DGA) used by malware for command-and-control (C2) communication
Why this is correct
DGA malware generates many pseudo-random domain names to avoid static blocklists and to locate its C2 server. The short TTLs and high volume of unique, random-looking queries from one host strongly indicate DGA activity. The host is likely attempting to resolve one of the domains that the attacker has registered to establish C2.
- ✗
DNS tunneling used to exfiltrate sensitive data
Why it's wrong here
DNS tunneling typically involves encoding data in DNS queries and responses, often with long, unusual subdomains and high query volume to a single domain. The scenario shows many different random domains with short TTLs, not large volumes of data encoded in queries to one domain. This pattern is more consistent with DGA than with tunneling.
Visual reference
Go deeper
Related to this question
About these practice questions
This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.