Courseiva
Security Monitoring →hardMultiple Choice

200-201 Security Monitoring Practice Question

A security analyst is using Cisco Umbrella and notices a high volume of DNS queries from a single internal host to randomly generated domain names that do not resolve. The queries are for domains like 'a1b2c3d4.com', 'e5f6g7h8.net', etc. What type of malicious activity is most likely occurring?

⚠ Common exam trap

Candidates often confuse DGA with DNS tunneling; DGA generates many random domains, while tunneling uses a single domain with encoded data.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Domain generation algorithm (DGA) used by malware for command and control.

The high volume of DNS queries to randomly generated, non-resolving domains is a hallmark of a domain generation algorithm (DGA). Malware uses DGAs to generate many potential C2 domains, hoping one will resolve and allow communication. Cisco Umbrella logs these queries, and the pattern is a strong indicator of infection. DNS tunneling and misconfigurations would present differently.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Domain generation algorithm (DGA) used by malware for command and control.

    Why this is correct

    DGAs generate many random domain names that malware queries to locate its C2 server. The high volume of non-resolving queries to random domains is a classic sign of DGA activity. Cisco Umbrella would log these queries, and the pattern of random, unresolvable domains strongly indicates malware attempting to establish C2 communication.

  • ✗

    A phishing campaign attempting to redirect users to fake websites.

    Why it's wrong here

    Phishing campaigns typically involve emails with links to malicious domains that resolve. The high volume of non-resolving random domains from a single host is not characteristic of phishing, which targets many users and often uses a few domains. This pattern is more consistent with automated malware behavior like DGA.

  • ✗

    A misconfigured application repeatedly querying non-existent domains.

    Why it's wrong here

    A misconfigured application might query non-existent domains, but typically the domains would be consistent (e.g., a typo in a configuration). The random, algorithmically generated nature of the domains here is not typical of a simple misconfiguration. The randomness suggests deliberate generation by malware, not an accident.

  • ✗

    DNS tunneling for data exfiltration.

    Why it's wrong here

    DNS tunneling involves encoding data in DNS queries and responses, often to a specific domain controlled by the attacker. The queries would typically resolve and contain encoded data, not be random and non-resolving. The pattern here is of many different random domains, which is more indicative of DGA than tunneling.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.