CompTIA CySA+ (CS0-003)Vulnerability ManagementHard
A security analyst is investigating a suspected data exfiltration incident. They find the following log entries from an internal DNS server:
- ACommand and Control
- BReconnaissance
- CExfiltration
- DLateral Movement
Show answer & explanationAnswer & explanation
Correct answer: C. Exfiltration
The log entries show repeated, unusually long DNS queries for subdomains that encode data (e.g., 'data-chunk-1.stoleninfo.attacker.com'). This technique, known as DNS tunneling, is a common method for exfiltrating data out of a network, making 'Exfiltration' the most appropriate MITRE ATT&CK tactic.
Why the other options are wrong
- A. Command and Control typically involves establishing a persistent communication channel for remote control, though it can sometimes use DNS, the pattern here is more indicative of data transfer.
- B. Reconnaissance involves gathering information about the target, which would typically involve different DNS query patterns, such as looking up public records or common services, not encoding large data chunks.
- D. Lateral Movement involves moving within the network, not necessarily sending data out via DNS.
MITRE ATT&CK: Exfiltration
Exfiltration is the tactic used by adversaries to steal data from an organization's network. This can involve various techniques to package, transfer, and remove data.
- Adversaries steal data by copying, packaging, and sending it out of the network.
- Common techniques include data compression, encryption, and tunneling protocols (e.g., DNS, ICMP, HTTP).
- Detection often involves monitoring network traffic for unusual data volumes, destinations, or protocols.
Memory trick: EX-FILM: The data 'exits' the 'film' (network) frame by frame.