CompTIA PenTest+ (PT0-003)Attacks and ExploitsMedium

A penetration tester runs the command dig axfr @ns1.example.com example.com against a target's authoritative name server and receives a complete list of every subdomain, internal hostname, and associated IP address for the domain. What does this result indicate?

  1. AThe domain relies on fast-flux DNS to hide malicious infrastructure
  2. BThe name server is vulnerable to DNS cache poisoning
  3. CThe name server allows unrestricted zone transfers (AXFR) to any requester
  4. DThe domain is using DNS tunneling for covert communication
Show answer & explanation

Correct answer: C. The name server allows unrestricted zone transfers (AXFR) to any requester

A successful AXFR request from an arbitrary, unauthorized host means the DNS server is misconfigured to permit zone transfers to anyone, leaking the entire DNS zone file, including internal hosts that were never meant to be public.

Why the other options are wrong

  • A. Fast-flux DNS rapidly rotates IPs to hide malicious hosts, not related to zone transfer misconfiguration.
  • B. Cache poisoning corrupts resolver caches with fake records; it does not explain a full zone dump.
  • D. DNS tunneling exfiltrates data through encoded DNS queries, unrelated to zone transfer output.

DNS Zone Transfer (AXFR) Misconfiguration

A DNS server vulnerability where zone transfer requests (AXFR) are allowed from unauthorized hosts, leaking the entire DNS zone including internal hostnames and IPs.

  • Zone transfers should be restricted to authorized secondary name servers only
  • Tools: dig axfr, host -t axfr, nslookup
  • Reveals internal infrastructure useful for further reconnaissance

Memory trick: AXFR leak = the phonebook for the entire company handed to a stranger

More Attacks and Exploits questions