Courseiva

200-201 Network Intrusion Analysis Practice Question

An analyst is investigating a potential DNS tunneling attack. Which characteristic in DNS traffic would most likely indicate DNS tunneling?

⚠ Common exam trap

200-201 often tests the confusion between DNS tunneling (data hidden in long, random query names) and DNS beaconing (regular-interval check-ins) or DNS amplification (large responses), so candidates who pick 'large payload' or 'regular intervals' miss the specific structural signature of tunneling.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

DNS queries with long, random-looking subdomains to a single domain.

DNS tunneling encodes data (e.g., stolen files, C2 commands) into the query name itself, so the attacker generates long, high-entropy subdomains like 'a8f3k2...exfil.attacker.com' under a single controlled domain. The randomness defeats signature-based detection, and the length maximizes the bytes smuggled per query. This pattern — many unique, long, random labels pointing to one authoritative domain — is the hallmark of tools such as iodine, dnscat2, and DNSExfiltrator.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    DNS queries with long, random-looking subdomains to a single domain.

    Why this is correct

    Long, random-looking subdomains encode exfiltrated data or command payloads, since DNS labels carry limited bytes per query. Repeated queries to one domain, rather than many domains, match tunnelling's need for a stable server endpoint. This pattern satisfies the stem's requirement for a characteristic distinguishing tunnelling from ordinary DNS resolution.

  • ✗

    Frequent DNS queries to the same domain at regular intervals.

    Why it's wrong here

    Regular-interval queries to one domain resemble beaconing, which malware command-and-control commonly produces, but DNS tunnelling is identified by high-volume queries with long, high-entropy subdomain labels carrying encoded data. It is tempting because both involve repeated DNS traffic, yet periodicity indicates beaconing rather than tunnelling.

  • ✗

    DNS queries for domains that are known to be malicious.

    Why it's wrong here

    Queries to known-malicious domains indicate blocklist hits or command-and-control contact, not tunnelling, which is detected through anomalous query volume, long encoded subdomain labels and high entropy. It is tempting because both are DNS threats, but reputation matching identifies known bad domains rather than tunnelling behaviour.

  • ✗

    DNS query responses with unusually large payload sizes.

    Why it's wrong here

    Large DNS response payloads suggest data exfiltration or oversized records, but tunnelling is characterised by high volumes of queries carrying encoded data in query names, not response size alone. It is tempting because tunnelling transfers data, yet the query side, not response payload, is the primary indicator.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.