Courseiva
Network Intrusion Analysis →mediumMultiple Choice

200-201 Network Intrusion Analysis Practice Question

An analyst observes a series of DNS queries for subdomains like 'ZGVzdGluYXRpb24= .malicious.com' where the subdomain part appears base64-encoded. The volume of DNS traffic from a single host is unusually high. Which exfiltration technique is most likely in use?

⚠ Common exam trap

The trap here is that candidates might see 'base64-encoded' and think of HTTP or other protocols, but the key indicator is the DNS queries themselves; DNS tunnelling specifically uses DNS as the transport, and the base64 encoding is just a way to fit data into DNS labels.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

DNS tunnelling

The base64-encoded subdomains and high volume of DNS queries from a single host are classic indicators of DNS tunnelling, where data is exfiltrated by encoding it into DNS query names (e.g., subdomains) sent to an attacker-controlled domain. DNS is often allowed through firewalls, making it an attractive covert channel. The base64 encoding allows arbitrary binary data to be transmitted as DNS labels, and the high query volume reflects the data transfer.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    FTP exfiltration

    Why it's wrong here

    FTP transfers files over dedicated TCP ports 20 and 21, producing no DNS query patterns and no base64-encoded subdomains. It is tempting because FTP is a classic exfiltration channel, but the observed high-volume DNS traffic carrying encoded labels indicates DNS tunnelling, not file transfer.

  • ✓

    DNS tunnelling

    Why this is correct

    Encoding data into DNS query names and pushing it to an authoritative server via high-volume lookups is DNS tunnelling. The base64 subdomains and abnormal query volume from one host match covert channel exfiltration rather than normal resolution traffic.

  • ✗

    HTTP POST exfiltration

    Why it's wrong here

    DNS tunnelling encodes data in query names, not HTTP bodies, so the base64 subdomains and query volume point to DNS, not POST. HTTP POST exfiltration is tempting because it is the commonest channel for stolen data, and would be correct where outbound TCP/80 or /443 to an attacker host is permitted.

  • ✗

    Steganography in images

    Why it's wrong here

    Steganography hides data inside image files, producing large HTTP or file transfers rather than encoded DNS labels. It would be correct where exfiltration rides inside picture uploads, not the base64 subdomain queries and DNS volume seen here.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.