Courseiva
Security MonitoringmediumMultiple ChoiceObjective-mapped

200-201 Security Monitoring Practice Question

An analyst suspects data exfiltration via DNS. Which log type would provide the most relevant information to confirm this?

⚠ Common exam trap

Cisco often tests the distinction between logs that record metadata (firewall logs) versus logs that record application-layer payloads (DNS logs), leading candidates to mistakenly choose firewall logs because they think 'all traffic passes through the firewall'.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

DNS logs

DNS logs capture all DNS queries and responses, including the domain names being resolved. Data exfiltration via DNS often involves encoding stolen data into DNS queries (e.g., subdomains of a controlled domain). By examining DNS logs for unusual query patterns, high query volumes, or long, random-looking subdomains, an analyst can directly confirm exfiltration activity.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Web server logs

    Why it's wrong here

    Web server logs show HTTP activity, not DNS.

  • Firewall logs

    Why it's wrong here

    Firewall logs show allowed/denied traffic but not DNS query details.

  • DNS logs

    Why this is correct

    DNS logs show query types, domains, and responses, ideal for detecting exfiltration.

  • IDS/IPS alerts

    Why it's wrong here

    IDS/IPS may detect but not provide full query details.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

Courseiva writes every 200-201 question from scratch — 979 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.