CompTIA CySA+ (CS0-003)Security OperationsHard
An analyst reviewing DNS server logs notices the following unusual pattern from a single internal host: query: a8f3c9d2e1b7.exfildata.com TYPE=TXT query: 7b2f9e4a1c6d.exfildata.com TYPE=TXT query: 3d8e1f6a9b2c.exfildata.com TYPE=TXT (thousands of similar queries per hour, each with unique 12-character hex subdomains) What malicious activity does this pattern most likely indicate?
- AA DNS cache poisoning attack
- BLegitimate content delivery network (CDN) load balancing
- CNormal DNSSEC zone signing operations
- DDNS tunneling for covert data exfiltration
Show answer & explanationAnswer & explanation
Correct answer: D. DNS tunneling for covert data exfiltration
High-volume queries with unique, randomized-looking hexadecimal subdomains to the same domain, using TXT records, are a hallmark of DNS tunneling, where data is encoded into subdomain labels to covertly exfiltrate information through DNS.
Why the other options are wrong
- A. Cache poisoning involves injecting forged responses into a resolver's cache, not outbound encoded queries.
- B. CDN load balancing does not produce unique encoded hex subdomains for every single query.
- C. DNSSEC zone signing involves cryptographic signature records (RRSIG/DNSKEY), not randomized subdomain data encoding.
DNS Tunneling
A covert channel technique that encodes data within DNS queries/responses (often as subdomain labels) to exfiltrate data or establish C2 while evading traditional network filters.
- Often uses TXT, NULL, or CNAME record types
- Subdomains appear random/high-entropy (base32/hex encoded)
- High query volume to a single domain is a key indicator
Memory trick: DNS tunneling = smuggling data through the mail system nobody inspects.