CompTIA CySA+ (CS0-003)Security OperationsMedium

A security analyst is investigating a suspected data exfiltration incident. Reviewing proxy logs, the analyst observes a large volume of outbound traffic from an internal host (10.10.10.50) to an external IP address (203.0.113.10) on a non-standard port, but the traffic appears to be legitimate HTTP/S. Further inspection of the traffic reveals highly obfuscated data within the HTTP User-Agent and Accept-Language headers. What type of exfiltration technique is most likely being employed?

  1. ADNS Tunneling
  2. BSMB Relay
  3. CICMP Tunneling
  4. DHTTP/HTTPS Tunneling
Show answer & explanation

Correct answer: D. HTTP/HTTPS Tunneling

HTTP/HTTPS tunneling involves encapsulating other protocols or data within HTTP/HTTPS traffic to bypass firewalls and proxy servers. The use of non-standard ports and obfuscated data within HTTP headers are strong indicators of this technique.

Why the other options are wrong

  • A. DNS tunneling would involve data exfiltration through DNS queries and responses, not HTTP/S traffic.
  • B. SMB relay is a credential theft attack, not a data exfiltration technique involving HTTP/S headers.
  • C. ICMP tunneling would involve data exfiltration using ICMP echo requests and replies, not HTTP/S traffic.

HTTP/HTTPS Tunneling

A technique where non-HTTP/S traffic or data is encapsulated within HTTP/HTTPS requests and responses to bypass network security controls.

  • Bypasses firewalls/proxies by blending with legitimate web traffic.
  • Often uses non-standard ports or obfuscated data in headers/payloads.
  • Commonly used for C2 communication or data exfiltration.

Memory trick: Data leaves through disguised tunnels.

More Security Operations questions