CompTIA CySA+ (CS0-003)Security OperationsMedium

A threat hunter is investigating a potential compromise on the corporate network. While analyzing NetFlow records, the hunter observes a workstation (192.168.1.50) initiating a large number of UDP connections to various external IP addresses on port 53. The data sizes for these UDP packets are consistently small (around 60-100 bytes), and the destination domains are often newly registered or appear to be algorithmically generated. Which of the following malicious activities is MOST consistent with these observations?

  1. ADNS tunneling for C2 or exfiltration
  2. BUDP flood DDoS attack
  3. CPeer-to-peer (P2P) file sharing
  4. DNTP amplification attack
Show answer & explanation

Correct answer: A. DNS tunneling for C2 or exfiltration

The pattern of numerous small UDP packets to external IPs on port 53 (DNS), especially with algorithmically generated or new domains, is a strong indicator of DNS tunneling. Attackers use this to establish command and control (C2) or exfiltrate data by encoding information within DNS queries and responses, making it difficult to detect as it blends with legitimate DNS traffic.

Why the other options are wrong

  • B. A UDP flood DDoS attack would involve a massive volume of traffic, likely with larger packet sizes, aimed at overwhelming a target, not small, consistent packet sizes and domain queries.
  • C. P2P file sharing typically involves a wider range of ports and much larger data transfers, not exclusively small UDP packets on port 53.
  • D. NTP amplification attacks use UDP port 123 (NTP) and involve sending small requests to NTP servers to elicit large responses, which is a different port and traffic pattern.

DNS Tunneling

DNS tunneling is a technique used by attackers to bypass security controls by encoding data within DNS queries and responses. It can be used for command and control (C2) communication, data exfiltration, or to establish covert channels over DNS.

  • Utilizes DNS protocol (port 53 UDP/TCP).
  • Hides malicious traffic within legitimate DNS traffic.
  • Often involves queries to unusual, long, or algorithmically generated domain names.

Memory trick: Covert channels hide secrets in plain sight.

More Security Operations questions