CompTIA CySA+ (CS0-003)Security OperationsMedium
A security analyst is investigating a suspected data exfiltration incident. Reviewing proxy logs, the analyst observes a large volume of outbound traffic from an internal host (10.10.10.50) to an external IP address (203.0.113.10) on a non-standard port, but the traffic appears to be legitimate HTTP/S. Further inspection of the traffic reveals highly obfuscated data within the HTTP User-Agent and Accept-Language headers. What type of exfiltration technique is most likely being employed?
- ADNS Tunneling
- BSMB Relay
- CICMP Tunneling
- DHTTP/HTTPS Tunneling
Show answer & explanationAnswer & explanation
Correct answer: D. HTTP/HTTPS Tunneling
HTTP/HTTPS tunneling involves encapsulating other protocols or data within HTTP/HTTPS traffic to bypass firewalls and proxy servers. The use of non-standard ports and obfuscated data within HTTP headers are strong indicators of this technique.
Why the other options are wrong
- A. DNS tunneling would involve data exfiltration through DNS queries and responses, not HTTP/S traffic.
- B. SMB relay is a credential theft attack, not a data exfiltration technique involving HTTP/S headers.
- C. ICMP tunneling would involve data exfiltration using ICMP echo requests and replies, not HTTP/S traffic.
HTTP/HTTPS Tunneling
A technique where non-HTTP/S traffic or data is encapsulated within HTTP/HTTPS requests and responses to bypass network security controls.
- Bypasses firewalls/proxies by blending with legitimate web traffic.
- Often uses non-standard ports or obfuscated data in headers/payloads.
- Commonly used for C2 communication or data exfiltration.
Memory trick: Data leaves through disguised tunnels.