CompTIA CySA+ (CS0-003)Security OperationsHard

An analyst reviewing DNS server logs notices the following unusual pattern from a single internal host: query: a8f3c9d2e1b7.exfildata.com TYPE=TXT query: 7b2f9e4a1c6d.exfildata.com TYPE=TXT query: 3d8e1f6a9b2c.exfildata.com TYPE=TXT (thousands of similar queries per hour, each with unique 12-character hex subdomains) What malicious activity does this pattern most likely indicate?

  1. AA DNS cache poisoning attack
  2. BLegitimate content delivery network (CDN) load balancing
  3. CNormal DNSSEC zone signing operations
  4. DDNS tunneling for covert data exfiltration
Show answer & explanation

Correct answer: D. DNS tunneling for covert data exfiltration

High-volume queries with unique, randomized-looking hexadecimal subdomains to the same domain, using TXT records, are a hallmark of DNS tunneling, where data is encoded into subdomain labels to covertly exfiltrate information through DNS.

Why the other options are wrong

  • A. Cache poisoning involves injecting forged responses into a resolver's cache, not outbound encoded queries.
  • B. CDN load balancing does not produce unique encoded hex subdomains for every single query.
  • C. DNSSEC zone signing involves cryptographic signature records (RRSIG/DNSKEY), not randomized subdomain data encoding.

DNS Tunneling

A covert channel technique that encodes data within DNS queries/responses (often as subdomain labels) to exfiltrate data or establish C2 while evading traditional network filters.

  • Often uses TXT, NULL, or CNAME record types
  • Subdomains appear random/high-entropy (base32/hex encoded)
  • High query volume to a single domain is a key indicator

Memory trick: DNS tunneling = smuggling data through the mail system nobody inspects.

More Security Operations questions