Courseiva
easyMultiple Choice

200-201 Practice Question: An analyst needs to determine if a host is…

An analyst needs to determine if a host is infected with malware that is attempting to contact a known malicious domain. Which log source is most appropriate for this analysis?

⚠ Common exam trap

Cisco often tests the distinction between network-level logs that contain domain names (DNS logs) versus those that only contain IP addresses (NetFlow), leading candidates to mistakenly choose NetFlow because they think it captures all network activity.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

DNS server logs

DNS server logs are the most appropriate source because they record all DNS queries made by hosts on the network. If a host is attempting to contact a known malicious domain, the DNS query for that domain will appear in the logs, allowing the analyst to identify the infected host by its source IP address and the timestamp of the query.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Syslog from the host

    Why it's wrong here

    Host syslog records local system and application events but does not reliably capture outbound DNS queries or connections to external domains. Syslog suits host-level event correlation, not identifying command-and-control traffic to a known malicious domain.

  • ✗

    NetFlow records

    Why it's wrong here

    NetFlow records IP flows and volumes but omits DNS query names, so a domain lookup cannot be confirmed. NetFlow suits traffic-volume baselining and anomaly detection, not resolving whether a host contacted a specific malicious domain.

  • ✓

    DNS server logs

    Why this is correct

    DNS server logs record every queried domain and the requesting client's IP address, directly satisfying the requirement to identify a host contacting a known malicious domain. Unlike proxy or firewall logs, which capture connections rather than name resolution, DNS logs expose the attempted lookup itself, even when the subsequent connection is blocked or fails.

  • ✗

    Data loss prevention (DLP) logs

    Why it's wrong here

    DLP logs record policy violations around sensitive data leaving sanctioned channels, such as email attachments or uploads to cloud storage, so they contain no DNS query or connection records for a malicious domain. They would be the right source when investigating whether confidential files were exfiltrated, not when tracing command-and-control beaconing from an infected host.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.