Courseiva
Security Monitoring →hardMultiple Choice

200-201 Security Monitoring Practice Question

An analyst is investigating a potential data exfiltration via DNS. In Zeek DNS logs, the analyst sees many queries for subdomains like 'a1b2c3.malicious.com', 'd4e5f6.malicious.com' etc. from an internal host. Which technique is likely being used?

⚠ Common exam trap

Cisco often tests the distinction between DNS tunneling (data exfiltration) and DNS amplification (DDoS), where candidates mistakenly associate any unusual DNS pattern with a volumetric attack rather than a covert channel.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

DNS tunneling

The repeated pattern of unique, seemingly random subdomains (e.g., 'a1b2c3.malicious.com') from a single internal host is a classic indicator of DNS tunneling. This technique encodes exfiltrated data into DNS query subdomains, leveraging the fact that DNS traffic is often allowed through firewalls. The malicious server decodes the subdomain strings to reconstruct the stolen data.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    DNS cache poisoning

    Why it's wrong here

    Cache poisoning injects forged records into a resolver's cache so subsequent lookups return attacker-controlled addresses; it does not generate sequential encoded subdomain queries from one internal host. It is tempting because both involve malicious DNS, but poisoning redirects resolution, while the correct answer is DNS tunnelling, which encodes exfiltrated data in query labels.

  • ✗

    DNS amplification

    Why it's wrong here

    DNS amplification floods a victim with large responses by spoofing their address, so it produces no unique encoded subdomain labels from an internal host. It is tempting because both abuse DNS, but amplification is a denial-of-service reflection technique, whereas the correct answer is DNS tunnelling, which encodes exfiltrated data in query names.

  • ✓

    DNS tunneling

    Why this is correct

    DNS tunneling uses subdomains to encode data.

  • ✗

    DNS zone transfer

    Why it's wrong here

    A zone transfer copies an entire zone's records from an authoritative server; it does not generate many random subdomain queries. It is tempting because misconfigured servers permitting AXFR expose DNS data, but that is reconnaissance against a nameserver, not tunnelled exfiltration from an internal host.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.