200-201 Network Intrusion Analysis Practice Question
A security analyst observes periodic outbound HTTPS connections to an unusual domain that resolves to different IP addresses each time. This behavior is most indicative of:
⚠ Common exam trap
200-201 often tests the confusion between DGA beaconing and DNS tunnelling — both involve DNS, but DGA is about rotating domains for C2 check-ins, while tunnelling is about encoding data inside DNS queries.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Beaconing using DGA
Periodic outbound HTTPS connections to an unusual domain that resolves to different IPs each time is the classic signature of beaconing using a Domain Generation Algorithm (DGA). Malware uses DGA to generate many pseudo-random domains and rotates through them to evade blocklists, while beaconing provides regular check-ins to C2.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Exfiltration via FTP
Why it's wrong here
FTP exfiltration uses FTP control and data channels, commonly ports 20 and 21, to move files outward; the stem describes HTTPS connections instead. It is tempting because exfiltration also involves periodic outbound transfers to an external host, and would be correct if FTP sessions carried the data. The protocol mismatch rules it out.
- ✗
DNS tunnelling
Why it's wrong here
DNS tunnelling encodes data inside DNS queries and responses to a controlled domain, typically using TXT or other record types, rather than repeated HTTPS sessions. It is tempting because it also abuses an unusual domain, and would be correct if DNS query volume or payload size were anomalous. HTTPS traffic points elsewhere.
- ✗
Port scanning
Why it's wrong here
Port scanning probes many destination ports on hosts to find listening services; it does not generate periodic HTTPS sessions to one domain whose DNS answers rotate. It is tempting because scanning also produces repeated connection attempts, and would be correct for reconnaissance against a target range. The rotating-IP domain pattern indicates command-and-control.
- ✓
Beaconing using DGA
Why this is correct
Periodic outbound HTTPS traffic combined with rotating IP resolutions points to domain generation algorithms, where malware cycles through algorithmically generated domains for command-and-control. The regular interval satisfies the beaconing constraint, while the shifting IP addresses reflect DGA domains resolving to changing infrastructure, distinguishing it from static command-and-control.
Visual reference
Go deeper
Related to this question
About these practice questions
This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.