hardMultiple ChoiceObjective-mapped
200-201 Practice Question: An analyst reviews NetFlow data and sees a single…
An analyst reviews NetFlow data and sees a single internal IP communicating with many external IPs on port 53, each with small UDP packets. The internal host is not a DNS server. What is the most likely explanation?
⚠ Common exam trap
Cisco often tests the distinction between the victim and the attacker in amplification attacks; the trap here is that candidates see many small UDP packets and assume the host is initiating queries (e.g., scanning or DNS lookups), rather than recognizing that the host is the victim receiving the amplified responses.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The host is the victim of a DNS amplification attack
The internal host is not a DNS server, yet it is sending small UDP packets to many external IPs on port 53. This is characteristic of a DNS amplification attack, where the attacker spoofs the victim's IP address and sends small queries to open DNS resolvers, which then send large responses to the victim. The NetFlow data shows the victim receiving the amplified traffic, not initiating it, making C correct.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The host is acting as a DNS server
Why it's wrong here
The host is not a DNS server.
- ✗
The host is performing recursive DNS lookups
Why it's wrong here
Recursive lookups go to a few servers, not many.
- ✓
The host is the victim of a DNS amplification attack
Why this is correct
The host's IP is spoofed as the source of queries to many open resolvers, causing replies to flood the host.
- ✗
The host is scanning for open DNS resolvers
Why it's wrong here
Scanning would show responses from many IPs, not requests from the host to many IPs.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-201 question from scratch — 979 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.