CompTIA CySA+ (CS0-003)Vulnerability ManagementHard

A security analyst is investigating a suspected data exfiltration incident. They find the following log entries from an internal DNS server:

  1. ACommand and Control
  2. BReconnaissance
  3. CExfiltration
  4. DLateral Movement
Show answer & explanation

Correct answer: C. Exfiltration

The log entries show repeated, unusually long DNS queries for subdomains that encode data (e.g., 'data-chunk-1.stoleninfo.attacker.com'). This technique, known as DNS tunneling, is a common method for exfiltrating data out of a network, making 'Exfiltration' the most appropriate MITRE ATT&CK tactic.

Why the other options are wrong

  • A. Command and Control typically involves establishing a persistent communication channel for remote control, though it can sometimes use DNS, the pattern here is more indicative of data transfer.
  • B. Reconnaissance involves gathering information about the target, which would typically involve different DNS query patterns, such as looking up public records or common services, not encoding large data chunks.
  • D. Lateral Movement involves moving within the network, not necessarily sending data out via DNS.

MITRE ATT&CK: Exfiltration

Exfiltration is the tactic used by adversaries to steal data from an organization's network. This can involve various techniques to package, transfer, and remove data.

  • Adversaries steal data by copying, packaging, and sending it out of the network.
  • Common techniques include data compression, encryption, and tunneling protocols (e.g., DNS, ICMP, HTTP).
  • Detection often involves monitoring network traffic for unusual data volumes, destinations, or protocols.

Memory trick: EX-FILM: The data 'exits' the 'film' (network) frame by frame.

More Vulnerability Management questions