Courseiva
Network Intrusion Analysis →mediumMultiple Choice

200-201 Network Intrusion Analysis Practice Question

Which of the following is a common indicator of DNS tunneling used for exfiltration?

⚠ Common exam trap

Cisco often tests the distinction between a general anomaly (like large DNS responses) and a specific tunneling indicator (long subdomain strings), where candidates mistakenly focus on response size or protocol choice rather than the query structure.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

DNS queries with long subdomain strings

DNS tunneling exploits the DNS protocol to encapsulate non-DNS data within DNS queries and responses. A common indicator is DNS queries with unusually long subdomain strings, as attackers encode exfiltrated data into the query name to bypass network security controls.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    DNS queries with long subdomain strings

    Why this is correct

    DNS tunnelling encodes stolen data into subdomain labels, so queries carrying long, high-entropy subdomain strings that exceed normal hostname lengths are a hallmark indicator. This satisfies the stem's requirement for a common exfiltration indicator, since legitimate DNS lookups rarely use such extended labels.

  • ✗

    Frequent DNS queries to known domains

    Why it's wrong here

    Queries to known, legitimate domains are ordinary resolution traffic; tunnelling indicators concern volume, size and record type anomalies, not destination reputation alone. It is tempting because beaconing to a fixed domain is suspicious, and it would be correct when the domain is newly registered or algorithmically generated.

  • ✗

    DNS responses with large payloads

    Why it's wrong here

    Large DNS response payloads are a hallmark of DNS tunnelling, since encoded exfiltration data is returned in TXT or NULL records. However, the question asks for an indicator of tunnelling used for exfiltration, where the outbound query carries the stolen data; oversized responses point to inbound command-and-control or download activity instead. This option is tempting because volume anomalies in either direction often accompany tunnelling.

  • ✗

    DNS queries using TCP instead of UDP

    Why it's wrong here

    TCP is a legitimate fallback for DNS when responses exceed UDP limits or are truncated, so its use alone does not indicate tunnelling. It is tempting because tunnelling tools often prefer TCP for reliability, and it would be correct when paired with sustained high-volume queries to one unusual domain.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.