nerdexam
Cisco

200-201 · Question #345

Refer to the exhibit. What is occurring?

The correct answer is B. possible DNS tunneling with encrypted communication through CNAMEs. The exhibit, which is not provided but implied, points to DNS tunneling, a technique where attackers smuggle data by encoding it within DNS queries and responses, frequently leveraging CNAME records.

Submitted by the_admin· Mar 6, 2026Network Intrusion Analysis

Question

Refer to the exhibit. What is occurring?

Exhibit

200-201 question #345 exhibit

Options

  • Apossible DNS amplification attack with requests that maximize data quantity
  • Bpossible DNS tunneling with encrypted communication through CNAMEs
  • Cpossible DNS cache poisoning with misdirects toward a fraudulent website
  • Dpossible botnet traffic with random MX querying to generate increased traffic

How the community answered

(53 responses)
  • A
    11% (6)
  • B
    62% (33)
  • C
    19% (10)
  • D
    8% (4)

Why each option

The exhibit, which is not provided but implied, points to DNS tunneling, a technique where attackers smuggle data by encoding it within DNS queries and responses, frequently leveraging CNAME records.

Apossible DNS amplification attack with requests that maximize data quantity

DNS amplification attacks involve sending small spoofed requests to DNS servers to generate large responses directed at a victim, focusing on volume, not data exfiltration via specific record types.

Bpossible DNS tunneling with encrypted communication through CNAMEsCorrect

DNS tunneling involves exfiltrating data or establishing command and control by encoding arbitrary data within DNS queries and responses, which can include using CNAME records to relay information.

Cpossible DNS cache poisoning with misdirects toward a fraudulent website

DNS cache poisoning involves injecting forged DNS records into a resolver's cache to redirect users to malicious websites, which is different from data exfiltration through DNS.

Dpossible botnet traffic with random MX querying to generate increased traffic

Botnet traffic might involve various DNS queries, but random MX querying to generate increased traffic doesn't specifically describe DNS tunneling for data exfiltration.

Concept tested: DNS tunneling attack identification

Source: https://learn.microsoft.com/en-us/azure/network-watcher/network-watcher-monitor-overview

Topics

#DNS tunneling#DNS attacks#network analysis#C2 communication

Community Discussion

No community discussion yet for this question.

Full 200-201 Practice