200-201 Network Intrusion Analysis Practice Question
An analyst observes a series of DNS queries for subdomains like 'ZGVzdGluYXRpb24= .malicious.com' where the subdomain part appears base64-encoded. The volume of DNS traffic from a single host is unusually high. Which exfiltration technique is most likely in use?
⚠ Common exam trap
The trap here is that candidates might see 'base64-encoded' and think of HTTP or other protocols, but the key indicator is the DNS queries themselves; DNS tunnelling specifically uses DNS as the transport, and the base64 encoding is just a way to fit data into DNS labels.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
DNS tunnelling
The base64-encoded subdomains and high volume of DNS queries from a single host are classic indicators of DNS tunnelling, where data is exfiltrated by encoding it into DNS query names (e.g., subdomains) sent to an attacker-controlled domain. DNS is often allowed through firewalls, making it an attractive covert channel. The base64 encoding allows arbitrary binary data to be transmitted as DNS labels, and the high query volume reflects the data transfer.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
FTP exfiltration
Why it's wrong here
FTP transfers files over dedicated TCP ports 20 and 21, producing no DNS query patterns and no base64-encoded subdomains. It is tempting because FTP is a classic exfiltration channel, but the observed high-volume DNS traffic carrying encoded labels indicates DNS tunnelling, not file transfer.
- ✓
DNS tunnelling
Why this is correct
Encoding data into DNS query names and pushing it to an authoritative server via high-volume lookups is DNS tunnelling. The base64 subdomains and abnormal query volume from one host match covert channel exfiltration rather than normal resolution traffic.
- ✗
HTTP POST exfiltration
Why it's wrong here
DNS tunnelling encodes data in query names, not HTTP bodies, so the base64 subdomains and query volume point to DNS, not POST. HTTP POST exfiltration is tempting because it is the commonest channel for stolen data, and would be correct where outbound TCP/80 or /443 to an attacker host is permitted.
- ✗
Steganography in images
Why it's wrong here
Steganography hides data inside image files, producing large HTTP or file transfers rather than encoded DNS labels. It would be correct where exfiltration rides inside picture uploads, not the base64 subdomain queries and DNS volume seen here.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.