CompTIA PenTest+ (PT0-003)Post-exploitation and Lateral MovementHard

A penetration tester has established a foothold on a Windows domain controller. The tester needs to exfiltrate critical Active Directory database files (NTDS.dit) without triggering immediate alerts. Which of the following methods would be MOST suitable for a covert data exfiltration?

  1. AUsing 'Metasploit's post/windows/gather/hashdump' module and copying hashes to a C2.
  2. BCompressing NTDS.dit and sending it via email through an internal mail server.
  3. CDirectly copying NTDS.dit to an external FTP server over the corporate network.
  4. DLeveraging DNS tunneling to slowly transfer chunks of the NTDS.dit file to a controlled DNS server.
Show answer & explanation

Correct answer: D. Leveraging DNS tunneling to slowly transfer chunks of the NTDS.dit file to a controlled DNS server.

DNS tunneling is highly covert for data exfiltration because it abuses legitimate DNS traffic, which is rarely inspected for malicious payloads. It allows for slow but steady data transfer without triggering typical network security alerts.

Why the other options are wrong

  • A. This module extracts hashes but doesn't exfiltrate the NTDS.dit file itself, which was the stated goal. While hashes are critical, the question specifically asks about the file.
  • B. Sending large attachments via email is likely to be flagged by email security gateways.
  • C. Direct FTP transfer is easily detectable by network monitoring and IDS/IPS.

DNS Tunneling for Exfiltration

A covert data exfiltration technique that encodes data within DNS queries and responses, allowing it to bypass firewalls and traditional network monitoring.

  • Abuses legitimate DNS protocol for data transfer.
  • Often bypasses IDS/IPS as DNS traffic is rarely deep-inspected.
  • Typically slow due to DNS packet size limitations, but highly stealthy.

Memory trick: To steal data invisibly, you need clever packaging and a ghost path.

More Post-exploitation and Lateral Movement questions