Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Cisco 200-201 Exam - Topic 7 Question 79 Discussion

A network engineer noticed in the NetFlow report that internal hosts are sending many DNS requests to external DNS servers A SOC analyst checked the endpoints and discovered that they are infected and became part of the botnet Endpoints are sending multiple DNS requests but with spoofed IP addresses of valid external sources What kind of attack are infected endpoints involved in1?
D) DNS amplification
A) DNS hijacking
B) DNS tunneling
C) DNS flooding

Cisco 200-201 Exam - Topic 7 Question 79 Discussion

Actual exam question for Cisco's 200-201 exam
Question #: 79
Topic #: 7
[All 200-201 Questions]

A network engineer noticed in the NetFlow report that internal hosts are sending many DNS requests to external DNS servers A SOC analyst checked the endpoints and discovered that they are infected and became part of the botnet Endpoints are sending multiple DNS requests but with spoofed IP addresses of valid external sources What kind of attack are infected endpoints involved in1?

Show Suggested Answer Hide Answer
Suggested Answer: D

Contribute your Thoughts:

0/2000 characters
Stevie
9 months ago
I'm with you, Felicitas. Spoofed IPs scream hijacking!
upvoted 0 times
...
Refugia
10 months ago
Wait, are we sure it's not just a misconfiguration?
upvoted 0 times
...
Junita
10 months ago
Definitely DNS flooding. Too many requests!
upvoted 0 times
...
Kerry
10 months ago
I think it's more like DNS tunneling.
upvoted 0 times
...
Felicitas
10 months ago
Sounds like DNS hijacking to me.
upvoted 0 times
...
Jenise
10 months ago
I feel like this could be DNS tunneling too, but the spoofing aspect is throwing me off. I need to review my notes on the differences between these attacks.
upvoted 0 times
...
Marci
11 months ago
I think it might be DNS flooding since the endpoints are sending so many requests. I recall a similar practice question where the focus was on overwhelming the server.
upvoted 0 times
...
Jillian
11 months ago
This sounds a lot like DNS amplification to me, especially with the multiple requests. I practiced a question on that last week, but I’m not 100% confident.
upvoted 0 times
...
Charlene
11 months ago
I remember studying about DNS attacks, but I'm not entirely sure which one fits here. The spoofed IPs make me think it's something like DNS hijacking, but I could be wrong.
upvoted 0 times
...
Amie
11 months ago
I'm a little confused here. The question mentions the hosts being part of a botnet, but it also talks about spoofed IP addresses. Is this some kind of DNS hijacking attack? I'm not sure which one to choose.
upvoted 0 times
...
Royal
11 months ago
Hmm, I'm not sure about this one. The question mentions spoofed IP addresses, but it also talks about the hosts being part of a botnet. Could it be a DNS flooding attack instead?
upvoted 0 times
...
Richelle
11 months ago
This one seems pretty straightforward. The infected endpoints are sending spoofed DNS requests, so it's got to be a DNS amplification attack.
upvoted 0 times
...
Oneida
11 months ago
Okay, let me think this through. The infected endpoints are sending multiple DNS requests, but with spoofed IP addresses of valid external sources. That sounds like they're trying to amplify the attack, so I'm going to go with DNS amplification.
upvoted 0 times
...
Jacob
11 months ago
Okay, let's see. The "Voice of the Employee" seems like the most logical choice here, since employee-related factors would be the primary concern. But I'll double-check the other options just to be sure.
upvoted 0 times
...
Temeka
11 months ago
Key strategy: underline the critical details and look for logical consistency between the two terms I'm selecting.
upvoted 0 times
...
Letha
11 months ago
I'm a bit confused by some of these choices. I'll need to review the material again to make sure I understand the best practices for large systems.
upvoted 0 times
...
Heike
11 months ago
Okay, I've got this. The key is to ensure the cluster nodes have similar hardware resources so the load can be evenly distributed. I'm pretty confident option A is the right recommendation here.
upvoted 0 times
...
Lea
2 years ago
Ooh, this one's got me stumped. I'm torn between C and D. Anyone want to help a buddy out?
upvoted 0 times
...
Valda
2 years ago
Hmm, I was leaning towards DNS flooding, but the spoofed IPs make me second-guess that. DNS amplification seems like the best answer here.
upvoted 0 times
...
Kathryn
2 years ago
Hey buddy, no cheating allowed! Although, I'm feeling generous... I'd say go with D. DNS amplification. The spoofed IPs are the key giveaway.
upvoted 0 times
...
Rashida
2 years ago
Haha, nice try, Candidate 4. But Candidate 2's got the right idea. D is definitely the way to go on this one.
upvoted 0 times
Glory
2 years ago
Candidate 1
upvoted 0 times
...
Thomasena
2 years ago
Candidate 2
upvoted 0 times
...
...

Save Cancel