easyMultiple Choice
200-201 Practice Question: An analyst needs to determine if a host is…
An analyst needs to determine if a host is infected with malware that is attempting to contact a known malicious domain. Which log source is most appropriate for this analysis?
⚠ Common exam trap
Cisco often tests the distinction between network-level logs that contain domain names (DNS logs) versus those that only contain IP addresses (NetFlow), leading candidates to mistakenly choose NetFlow because they think it captures all network activity.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
DNS server logs
DNS server logs are the most appropriate source because they record all DNS queries made by hosts on the network. If a host is attempting to contact a known malicious domain, the DNS query for that domain will appear in the logs, allowing the analyst to identify the infected host by its source IP address and the timestamp of the query.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Syslog from the host
Why it's wrong here
Host syslog records local system and application events but does not reliably capture outbound DNS queries or connections to external domains. Syslog suits host-level event correlation, not identifying command-and-control traffic to a known malicious domain.
- ✗
NetFlow records
Why it's wrong here
NetFlow records IP flows and volumes but omits DNS query names, so a domain lookup cannot be confirmed. NetFlow suits traffic-volume baselining and anomaly detection, not resolving whether a host contacted a specific malicious domain.
- ✓
DNS server logs
Why this is correct
DNS server logs record every queried domain and the requesting client's IP address, directly satisfying the requirement to identify a host contacting a known malicious domain. Unlike proxy or firewall logs, which capture connections rather than name resolution, DNS logs expose the attempted lookup itself, even when the subsequent connection is blocked or fails.
- ✗
Data loss prevention (DLP) logs
Why it's wrong here
DLP logs record policy violations around sensitive data leaving sanctioned channels, such as email attachments or uploads to cloud storage, so they contain no DNS query or connection records for a malicious domain. They would be the right source when investigating whether confidential files were exfiltrated, not when tracing command-and-control beaconing from an infected host.
Visual reference
Go deeper
Related to this question
About these practice questions
This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.