CompTIA CySA+ (CS0-003)Incident Response and ManagementMedium
A security analyst is reviewing network flow logs and observes an unusual volume of outbound traffic from a database server to multiple external IP addresses over port 53 (DNS). The database server should not be initiating external DNS queries, especially not at this volume. An excerpt from the logs is below: ``` TIME SRC_IP DST_IP SPORT DPORT PROTO BYTES 16:34:01 192.168.1.10 1.2.3.4 49876 53 UDP 128 16:34:01 192.168.1.10 5.6.7.8 49877 53 UDP 128 16:34:02 192.168.1.10 9.10.11.12 49878 53 UDP 128 16:34:02 192.168.1.10 13.14.15.16 49879 53 UDP 128 ``` Which type of attack is MOST likely indicated by this activity?
- ASQL Injection
- BDNS Tunneling
- CPort Scanning
- DDDoS Attack
Show answer & explanationAnswer & explanation
Correct answer: B. DNS Tunneling
DNS tunneling involves encapsulating other protocols' data within DNS queries and responses. The high volume of outbound DNS queries from a server that shouldn't be making them, especially to various external IPs, is a strong indicator of an attacker using DNS for command and control or data exfiltration, as port 53 is often allowed outbound.
Why the other options are wrong
- A. SQL injection targets databases via web applications, typically not generating high volumes of outbound DNS traffic.
- C. Port scanning involves sending probes to many ports/IPs to discover open services, not typically generating high-volume outbound DNS queries from a single source.
- D. A DDoS attack is typically inbound traffic overwhelming a target, not high outbound DNS traffic from an internal server.
DNS Tunneling
A technique that encodes data of other protocols inside DNS queries and responses to create a covert communication channel, often used for data exfiltration or command and control (C2) by bypassing firewalls.
- Uses port 53 (DNS) for communication.
- Often seen as high volume of unusual DNS queries.
- Bypasses many security controls due to allowed DNS traffic.
Memory trick: Look for traffic that's 'out of place' and using 'allowed' ports for 'wrong' purposes.