CompTIA SecurityX (CAS-005)Security OperationsEasy
A security analyst is investigating a suspected data exfiltration incident. They discover that a large volume of data was transferred from an internal server to an external IP address over TCP port 53. Further investigation reveals that the data was encapsulated within DNS queries and responses, using a custom protocol. Which exfiltration technique is being used?
- AICMP exfiltration
- BDNS exfiltration
- CSSH tunneling
- DHTTP tunneling
Show answer & explanationAnswer & explanation
Correct answer: B. DNS exfiltration
The scenario explicitly states that data was transferred over TCP port 53 (the standard DNS port) and encapsulated within DNS queries and responses. This is the definition of DNS exfiltration, a technique used to bypass firewalls and intrusion detection systems.
Why the other options are wrong
- A. ICMP exfiltration uses ICMP packets for data transfer, not DNS queries.
- C. SSH tunneling uses TCP port 22 for encrypted data transfer, not port 53 or DNS queries.
- D. HTTP tunneling uses TCP ports 80/443 for data transfer, not port 53.
DNS Exfiltration
A technique where attackers encode data within DNS queries and responses to bypass security controls and transfer sensitive information out of a network. It leverages the legitimate and often unrestricted nature of DNS traffic.
- Uses DNS queries/responses for data transfer.
- Operates on TCP/UDP port 53.
- Often bypasses firewalls due to DNS whitelist rules.
Memory trick: Exfiltrate Data by Hiding It in Plain Sight.