nerdexam
Cisco

200-201 · Question #471

Refer to the exhibit. A network engineer received a report that a host is communicating with unknown domains on the internet. The network engineer collected packet capture but could not determine…

The correct answer is D. tunneling. The presence of the prefix dnscat in all queries strongly suggests that this is related to DNSCat or DNSCat2, which are tools commonly used for DNS tunneling. DNS tunneling involves encoding data into DNS queries and responses to establish a covert communication channel. This…

Submitted by viktor_hu· Mar 6, 2026Network Intrusion Analysis

Question

Refer to the exhibit. A network engineer received a report that a host is communicating with unknown domains on the internet. The network engineer collected packet capture but could not determine the technique or the payload used. What technique is the attacker using?

Exhibit

200-201 question #471 exhibit

Options

  • Ateardrop
  • Bamplification
  • Csession hijacking
  • Dtunneling

How the community answered

(64 responses)
  • A
    5% (3)
  • B
    3% (2)
  • C
    13% (8)
  • D
    80% (51)

Explanation

The presence of the prefix dnscat in all queries strongly suggests that this is related to DNSCat or DNSCat2, which are tools commonly used for DNS tunneling. DNS tunneling involves encoding data into DNS queries and responses to establish a covert communication channel. This can be used for exfiltrating data or for maintaining a backdoor communication channel to the network, bypassing traditional firewall rules since DNS is often allowed through most firewalls. The types of records queried (TXT, CNAME, MX) are commonly used for tunneling because they can store arbitrary data, making it easier to encode and transmit information within these DNS Teardrop refers to a denial-of-service attack that sends fragmented packets, not relevant here. Amplification is a form of DDoS attack using large responses to small queries, which is not Session hijacking involves taking over an existing session, which does not match the observed traffic pattern in this exhibit.

Topics

#network tunneling#covert channels#network anomalies#packet analysis

Community Discussion

No community discussion yet for this question.

Full 200-201 Practice