Courseiva
Network Intrusion Analysis →mediumMultiple Choice

200-201 Network Intrusion Analysis Practice Question

A security analyst observes periodic outbound HTTPS connections to an unusual domain that resolves to different IP addresses each time. This behavior is most indicative of:

⚠ Common exam trap

200-201 often tests the confusion between DGA beaconing and DNS tunnelling — both involve DNS, but DGA is about rotating domains for C2 check-ins, while tunnelling is about encoding data inside DNS queries.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Beaconing using DGA

Periodic outbound HTTPS connections to an unusual domain that resolves to different IPs each time is the classic signature of beaconing using a Domain Generation Algorithm (DGA). Malware uses DGA to generate many pseudo-random domains and rotates through them to evade blocklists, while beaconing provides regular check-ins to C2.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Exfiltration via FTP

    Why it's wrong here

    FTP exfiltration uses FTP control and data channels, commonly ports 20 and 21, to move files outward; the stem describes HTTPS connections instead. It is tempting because exfiltration also involves periodic outbound transfers to an external host, and would be correct if FTP sessions carried the data. The protocol mismatch rules it out.

  • ✗

    DNS tunnelling

    Why it's wrong here

    DNS tunnelling encodes data inside DNS queries and responses to a controlled domain, typically using TXT or other record types, rather than repeated HTTPS sessions. It is tempting because it also abuses an unusual domain, and would be correct if DNS query volume or payload size were anomalous. HTTPS traffic points elsewhere.

  • ✗

    Port scanning

    Why it's wrong here

    Port scanning probes many destination ports on hosts to find listening services; it does not generate periodic HTTPS sessions to one domain whose DNS answers rotate. It is tempting because scanning also produces repeated connection attempts, and would be correct for reconnaissance against a target range. The rotating-IP domain pattern indicates command-and-control.

  • ✓

    Beaconing using DGA

    Why this is correct

    Periodic outbound HTTPS traffic combined with rotating IP resolutions points to domain generation algorithms, where malware cycles through algorithmically generated domains for command-and-control. The regular interval satisfies the beaconing constraint, while the shifting IP addresses reflect DGA domains resolving to changing infrastructure, distinguishing it from static command-and-control.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.