CompTIA CySA+ (CS0-003)Security OperationsMedium

A threat hunter reviews DNS resolver logs and observes a single infected host querying hundreds of unique, algorithmically generated hostnames such as 'xk93jdla.com', 'plq82basd.net', and 'vt4mqzo.org' within a five-minute window, most returning NXDOMAIN. Which technique is most likely being used by the malware?

  1. ADomain generation algorithm (DGA)
  2. BDNS cache poisoning
  3. CDNS tunneling
  4. DFast flux DNS
Show answer & explanation

Correct answer: A. Domain generation algorithm (DGA)

Malware using a DGA generates large numbers of pseudo-random domain names on a schedule so it can locate its C2 server even if some domains are taken down or blocklisted; most attempts fail (NXDOMAIN) until the correct active domain is reached. DNS tunneling encodes data in queries to a single fixed domain, fast flux rapidly rotates IP addresses behind a stable domain name, and cache poisoning corrupts a resolver's cache with false records.

Why the other options are wrong

  • B. Cache poisoning injects false records into a resolver, unrelated to random domain generation.
  • C. Tunneling uses a consistent domain to exfiltrate data in subdomain labels, not many random domain names.
  • D. Fast flux rotates IP addresses for one domain, not the domain names themselves.

Domain Generation Algorithm (DGA)

An algorithm malware uses to generate a large number of pseudo-random domain names, one or a few of which the attacker has registered as active C2 infrastructure, making blocklisting difficult.

  • High volume of NXDOMAIN responses is a key indicator
  • Domains often have random-looking, unpronounceable strings
  • Seeded by date/time so both malware and attacker can compute matching domains

Memory trick: 'DGA rolls dice on domains' - most rolls miss (NXDOMAIN), one hits the C2 jackpot.

More Security Operations questions