CompTIA SecurityX (CAS-005)Security OperationsMedium

A security analyst is performing a forensic investigation on a potentially compromised Windows server. During the analysis of network connections, the analyst observes suspicious outbound UDP traffic on port 53 to external DNS servers, with unusually large DNS query responses containing non-standard data. The server's primary role is an internal file share, and it has no legitimate reason to initiate such external DNS queries. Which type of data exfiltration technique does this MOST strongly suggest?

  1. AFTP exfiltration
  2. BHTTP tunneling
  3. CSMB relay
  4. DDNS tunneling
Show answer & explanation

Correct answer: D. DNS tunneling

The observation of unusually large DNS query responses containing non-standard data, coupled with outbound UDP/53 traffic to external DNS servers from a server that shouldn't be initiating such traffic, is a strong indicator of DNS tunneling. This technique leverages DNS queries and responses to exfiltrate data or establish a C2 channel.

Why the other options are wrong

  • A. FTP exfiltration would involve traffic over TCP port 20/21, not UDP port 53, and would resemble file transfers.
  • B. HTTP tunneling would involve traffic over TCP port 80/443, not UDP port 53, and would look like web traffic.
  • C. SMB relay is a type of credential theft or lateral movement, not typically a direct data exfiltration method via DNS traffic.

DNS Tunneling

DNS tunneling is a data exfiltration or command-and-control technique that encodes data within DNS queries and responses to bypass firewalls and security controls.

  • Uses UDP port 53, often overlooked by network defenses.
  • Data is encapsulated within subdomains of DNS queries or TXT/NULL records.
  • Can be used for C2 communication or data exfiltration.

Memory trick: Hidden Data Exits Covertly.

More Security Operations questions