200-201 Network Intrusion Analysis Practice Question
Which of the following is a common indicator of DNS tunneling used for exfiltration?
⚠ Common exam trap
Cisco often tests the distinction between a general anomaly (like large DNS responses) and a specific tunneling indicator (long subdomain strings), where candidates mistakenly focus on response size or protocol choice rather than the query structure.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
DNS queries with long subdomain strings
DNS tunneling exploits the DNS protocol to encapsulate non-DNS data within DNS queries and responses. A common indicator is DNS queries with unusually long subdomain strings, as attackers encode exfiltrated data into the query name to bypass network security controls.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
DNS queries with long subdomain strings
Why this is correct
DNS tunnelling encodes stolen data into subdomain labels, so queries carrying long, high-entropy subdomain strings that exceed normal hostname lengths are a hallmark indicator. This satisfies the stem's requirement for a common exfiltration indicator, since legitimate DNS lookups rarely use such extended labels.
- ✗
Frequent DNS queries to known domains
Why it's wrong here
Queries to known, legitimate domains are ordinary resolution traffic; tunnelling indicators concern volume, size and record type anomalies, not destination reputation alone. It is tempting because beaconing to a fixed domain is suspicious, and it would be correct when the domain is newly registered or algorithmically generated.
- ✗
DNS responses with large payloads
Why it's wrong here
Large DNS response payloads are a hallmark of DNS tunnelling, since encoded exfiltration data is returned in TXT or NULL records. However, the question asks for an indicator of tunnelling used for exfiltration, where the outbound query carries the stolen data; oversized responses point to inbound command-and-control or download activity instead. This option is tempting because volume anomalies in either direction often accompany tunnelling.
- ✗
DNS queries using TCP instead of UDP
Why it's wrong here
TCP is a legitimate fallback for DNS when responses exceed UDP limits or are truncated, so its use alone does not indicate tunnelling. It is tempting because tunnelling tools often prefer TCP for reliability, and it would be correct when paired with sustained high-volume queries to one unusual domain.
Visual reference
Go deeper
Related to this question
About these practice questions
This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.