200-201 Security Monitoring Practice Question
A security analyst is using Cisco Umbrella and notices a high volume of DNS queries from a single internal host to randomly generated domain names that do not resolve. The queries are for domains like 'a1b2c3d4.com', 'e5f6g7h8.net', etc. What type of malicious activity is most likely occurring?
⚠ Common exam trap
Candidates often confuse DGA with DNS tunneling; DGA generates many random domains, while tunneling uses a single domain with encoded data.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Domain generation algorithm (DGA) used by malware for command and control.
The high volume of DNS queries to randomly generated, non-resolving domains is a hallmark of a domain generation algorithm (DGA). Malware uses DGAs to generate many potential C2 domains, hoping one will resolve and allow communication. Cisco Umbrella logs these queries, and the pattern is a strong indicator of infection. DNS tunneling and misconfigurations would present differently.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Domain generation algorithm (DGA) used by malware for command and control.
Why this is correct
DGAs generate many random domain names that malware queries to locate its C2 server. The high volume of non-resolving queries to random domains is a classic sign of DGA activity. Cisco Umbrella would log these queries, and the pattern of random, unresolvable domains strongly indicates malware attempting to establish C2 communication.
- ✗
A phishing campaign attempting to redirect users to fake websites.
Why it's wrong here
Phishing campaigns typically involve emails with links to malicious domains that resolve. The high volume of non-resolving random domains from a single host is not characteristic of phishing, which targets many users and often uses a few domains. This pattern is more consistent with automated malware behavior like DGA.
- ✗
A misconfigured application repeatedly querying non-existent domains.
Why it's wrong here
A misconfigured application might query non-existent domains, but typically the domains would be consistent (e.g., a typo in a configuration). The random, algorithmically generated nature of the domains here is not typical of a simple misconfiguration. The randomness suggests deliberate generation by malware, not an accident.
- ✗
DNS tunneling for data exfiltration.
Why it's wrong here
DNS tunneling involves encoding data in DNS queries and responses, often to a specific domain controlled by the attacker. The queries would typically resolve and contain encoded data, not be random and non-resolving. The pattern here is of many different random domains, which is more indicative of DGA than tunneling.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.