CompTIA SecurityX (CAS-005)Security OperationsEasy

A security analyst is reviewing network traffic logs and observes a high volume of DNS queries for non-existent domains (NXDOMAIN) originating from an internal server to various external DNS resolvers. This activity is persistent and occurs at unusual times. Which type of attack is most likely indicated by these observations?

  1. ADNS Amplification Attack
  2. BDomain Generation Algorithm (DGA)
  3. CCross-Site Scripting (XSS)
  4. DSQL Injection
Show answer & explanation

Correct answer: B. Domain Generation Algorithm (DGA)

The observed pattern of high-volume DNS queries for non-existent domains (NXDOMAIN) from an internal server is a classic indicator of a Domain Generation Algorithm (DGA). DGA is used by malware to generate a large number of potential C2 domains.

Why the other options are wrong

  • A. DNS Amplification attacks involve external attackers using victims' DNS servers, not internal servers querying external resolvers for non-existent domains.
  • C. Cross-Site Scripting (XSS) is a client-side attack that injects malicious scripts into web pages, not related to DNS query patterns.
  • D. SQL Injection targets databases and would not typically manifest as high NXDOMAIN queries.

Domain Generation Algorithm (DGA)

A technique used by malware to algorithmically generate a large number of new domain names that can be used as rendezvous points with their command and control (C2) servers. This makes it difficult for security teams to block all potential C2 domains.

  • Generates many domains for C2 communication.
  • Often results in high NXDOMAIN query rates.
  • Used to evade blacklisting of fixed C2 domains.

Memory trick: Malware Generates Domains to Connect and Control.

More Security Operations questions