200-201 Network Intrusion Analysis Practice Question
An analyst is investigating a potential DNS tunneling attack. Which characteristic in DNS traffic would most likely indicate DNS tunneling?
⚠ Common exam trap
200-201 often tests the confusion between DNS tunneling (data hidden in long, random query names) and DNS beaconing (regular-interval check-ins) or DNS amplification (large responses), so candidates who pick 'large payload' or 'regular intervals' miss the specific structural signature of tunneling.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
DNS queries with long, random-looking subdomains to a single domain.
DNS tunneling encodes data (e.g., stolen files, C2 commands) into the query name itself, so the attacker generates long, high-entropy subdomains like 'a8f3k2...exfil.attacker.com' under a single controlled domain. The randomness defeats signature-based detection, and the length maximizes the bytes smuggled per query. This pattern — many unique, long, random labels pointing to one authoritative domain — is the hallmark of tools such as iodine, dnscat2, and DNSExfiltrator.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
DNS queries with long, random-looking subdomains to a single domain.
Why this is correct
Long, random-looking subdomains encode exfiltrated data or command payloads, since DNS labels carry limited bytes per query. Repeated queries to one domain, rather than many domains, match tunnelling's need for a stable server endpoint. This pattern satisfies the stem's requirement for a characteristic distinguishing tunnelling from ordinary DNS resolution.
- ✗
Frequent DNS queries to the same domain at regular intervals.
Why it's wrong here
Regular-interval queries to one domain resemble beaconing, which malware command-and-control commonly produces, but DNS tunnelling is identified by high-volume queries with long, high-entropy subdomain labels carrying encoded data. It is tempting because both involve repeated DNS traffic, yet periodicity indicates beaconing rather than tunnelling.
- ✗
DNS queries for domains that are known to be malicious.
Why it's wrong here
Queries to known-malicious domains indicate blocklist hits or command-and-control contact, not tunnelling, which is detected through anomalous query volume, long encoded subdomain labels and high entropy. It is tempting because both are DNS threats, but reputation matching identifies known bad domains rather than tunnelling behaviour.
- ✗
DNS query responses with unusually large payload sizes.
Why it's wrong here
Large DNS response payloads suggest data exfiltration or oversized records, but tunnelling is characterised by high volumes of queries carrying encoded data in query names, not response size alone. It is tempting because tunnelling transfers data, yet the query side, not response payload, is the primary indicator.
Visual reference
About these practice questions
One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.