hardMultiple Choice
200-201 Practice Question: Based on the exhibit, what condition triggers an…
Exhibit
Refer to the exhibit.
{
"policy": "DNS Anomaly Detection",
"rule": {
"protocol": "udp",
"port": 53,
"threshold": 1000,
"window": 60,
"action": "alert"
}
}Based on the exhibit, what condition triggers an alert?
⚠ Common exam trap
Cisco often tests the distinction between a rate-based threshold (counting events over time) and a signature-based match (single event), leading candidates to confuse a single malicious query with a volumetric anomaly.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
More than 1000 DNS queries from a single source within 60 seconds.
The exhibit shows a rule configured to trigger an alert when the number of DNS queries from a single source IP exceeds 1000 within a 60-second sliding window. This is a rate-based threshold designed to detect DNS amplification or tunneling attacks, where a single host generates an abnormally high volume of DNS requests. Option A correctly describes this condition.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
More than 1000 DNS queries from a single source within 60 seconds.
Why this is correct
Threshold-based detection fires when a single source exceeds 1000 DNS queries in 60 seconds, matching the exhibit's configured trigger. This rate-based condition identifies DNS tunnelling or amplification activity, where abnormal query volume from one host signals compromise. The specified count and time window are the exact parameters the alert monitors.
- ✗
A single DNS query to a known malicious domain.
Why it's wrong here
The exhibit's threshold requires repeated or aggregate activity, so one isolated lookup does not meet it. It is tempting because a known malicious domain is high-fidelity intelligence, and it would be correct if the rule were reputation-based rather than volume-based.
- ✗
Any UDP traffic to port 53 exceeding 1000 packets per second.
Why it's wrong here
The exhibit counts UDP connections, not packet rate, so a packets-per-second threshold does not match the trigger condition. It is tempting because DNS tunnelling and flood detection often use packet rates, and it would be correct if the rule were expressed in packets per second.
- ✗
More than 1000 UDP connections to port 53 within 60 seconds.
Why it's wrong here
The exhibit specifies packets per second, not a cumulative connection count within a 60-second window, so this threshold misreads the trigger. It is tempting because volumetric DNS abuse detection is a genuine technique, and it would be correct if the rule counted connections over time.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.