CompTIA CySA+ (CS0-003)Security OperationsMedium
A security analyst is investigating a potential compromise on the corporate network. While analyzing DNS server logs, the analyst observes numerous unusual-looking DNS queries originating from an internal host (10.10.10.20) to an external domain (malicious.com). The queries often contain long, seemingly random strings as subdomains, and the responses typically return non-existent domain (NXDOMAIN) errors or very small data packets. What type of activity is this pattern most indicative of?
- ADNS Amplification Attack
- BDNS Tunneling
- CDomain Fronting
- DDNS Cache Poisoning
Show answer & explanationAnswer & explanation
Correct answer: B. DNS Tunneling
DNS tunneling leverages the DNS protocol to establish a covert communication channel. Attackers encode data within subdomains of DNS queries, and the responses (even NXDOMAIN or small data packets) can be used to exfiltrate data or establish command and control. The 'long, seemingly random strings as subdomains' and 'unusual-looking DNS queries' are key indicators.
Why the other options are wrong
- A. DNS amplification is a DoS attack that abuses open DNS resolvers, not a covert communication channel.
- C. Domain fronting hides the true endpoint of a connection using different domain names at different layers, not by encoding data in subdomains.
- D. DNS cache poisoning manipulates DNS resolvers' caches to redirect traffic, not for covert data transfer.
DNS Tunneling
A cyber attack method that encodes data of other programs or protocols within DNS queries and responses to tunnel through a firewall or for data exfiltration.
- Uses DNS queries (e.g., A, AAAA, TXT) to encapsulate data.
- Often involves long, random-looking subdomains.
- Can bypass firewalls that only inspect HTTP/S traffic.
Memory trick: DNS attacks hide data or redirect traffic.