200-201 exam dumps

200-201 practice question 292 of 405

Cisco Cybersecurity Associate. Associate level, Cisco. Free question with the correct answer and a full explanation.

200-201 Question 292

Select 3

A cybersecurity operations analyst is investigating a possible DNS tunneling attack in a corporate network. During the investigation, the analyst observes a high volume of DNS queries from a single client device, with domain names consisting of long, suspiciously random subdomains. What should the analyst focus on to confirm whether this is a DNS tunneling attack?

  1. A

    Check for unusually large DNS query payloads.

  2. B

    Analyze the entropy of the subdomain names in the DNS queries.

  3. C

    Verify if the domains being queried are associated with known malicious IP addresses.

  4. D

    Ensure the DNS server is properly configured to block non-standard ports.

  5. E

    Inspect the DNS query traffic for patterns of data exfiltration.

Show answer and explanation

Correct answers: A, B, E

Explanation

DNS tunneling is a technique where attackers encode data into DNS queries and responses to bypass network restrictions and exfiltrate data. To confirm DNS tunneling, analysts should investigate the size and nature of DNS payloads, analyze the randomness (entropy) of subdomains, and inspect for data exfiltration patterns. These behaviors are distinct indicators of DNS tunneling and can help differentiate it from legitimate DNS activity.

  • A. Correct.

    Unusually large DNS query payloads can indicate DNS tunneling, as attackers often encode data into DNS queries to bypass network restrictions.

  • B. Correct.

    High entropy in subdomain names (random, non-human-readable text) is a common sign of DNS tunneling because attackers encode data into these subdomains.

  • C. Incorrect.

    While malicious domains should be blocked, DNS tunneling often uses legitimate-looking domains, making this less relevant for confirming tunneling activity.

  • D. Incorrect.

    Blocking non-standard ports is a good security practice, but DNS tunneling typically operates on port 53, which is standard for DNS traffic.

  • E. Correct.

    Patterns of data exfiltration, such as repeated or sequential DNS queries with encoded data, are strong indicators of DNS tunneling.

Timed practice exam

Take a 200-201 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam