Courseiva
hardMultiple Choice

200-201 Practice Question: An analyst is investigating a potential data…

An analyst is investigating a potential data exfiltration. The logs show a series of DNS queries with subdomains that appear to be base64-encoded strings. Which technique is likely being used?

⚠ Common exam trap

Cisco often tests the distinction between DNS tunneling (data exfiltration via subdomain encoding) and DNS amplification (a volumetric DDoS attack), so candidates must recognize that base64-encoded subdomains point to tunneling, not amplification.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

DNS tunneling

DNS tunneling encodes data (e.g., exfiltrated files) into subdomains of DNS queries, which are then sent to a malicious authoritative DNS server controlled by the attacker. The base64-encoded subdomains in the logs are a classic indicator of this technique, as the attacker uses the DNS protocol to bypass network security controls and covertly transmit data.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    DNS tunneling

    Why this is correct

    DNS tunneling encapsulates data in DNS queries to exfiltrate information.

  • ✗

    DNS amplification

    Why it's wrong here

    DNS amplification is a reflection denial-of-service technique that spoofs source addresses to flood a victim with oversized responses; it moves no data out of the network. It is tempting because it also abuses DNS, but it would be the answer for volumetric DDoS, not for encoded subdomains carrying stolen data.

  • ✗

    Fast flux

    Why it's wrong here

    Fast flux rapidly rotates the IP addresses returned for a hostname to keep malicious infrastructure alive; the query names themselves stay constant and carry no payload. It is tempting because it also involves DNS abuse, but it would be correct when investigating resilient command-and-control hosting, not encoded exfiltration.

  • ✗

    Domain generation algorithm

    Why it's wrong here

    A domain generation algorithm produces large volumes of pseudo-random domain names that malware queries for rendezvous; those names are not base64-encoded data. It is tempting because it also generates many DNS queries, but it would be correct when the pattern shows algorithmically generated rendezvous domains, not encoded subdomains.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.