CompTIA SecurityX (CAS-005)Security OperationsMedium
A security analyst is investigating a potential data exfiltration incident. They have identified suspicious outbound network connections from an internal server to an unknown external IP address on TCP port 53. The DNS query logs for the internal server show legitimate-looking DNS queries, but the size of the responses is unusually large and consistent. What type of data exfiltration technique is this scenario most indicative of?
- ASMB Relay
- BICMP Tunneling
- CDNS Tunneling
- DHTTP/HTTPS Tunneling
Show answer & explanationAnswer & explanation
Correct answer: C. DNS Tunneling
DNS tunneling leverages the DNS protocol to tunnel data within DNS queries and responses. The scenario describes outbound connections on TCP port 53 (DNS), unusually large DNS responses, and legitimate-looking queries, all of which are classic indicators of DNS tunneling for data exfiltration.
Why the other options are wrong
- A. SMB relay involves intercepting and relaying SMB authentication requests, typically for lateral movement, not for data exfiltration over DNS port 53.
- B. ICMP tunneling uses the ICMP protocol (ping) to exfiltrate data, which would manifest as unusual ping traffic, not DNS queries.
- D. HTTP/HTTPS tunneling involves using web protocols (ports 80/443), not port 53, and would show web traffic, not DNS queries.
DNS Tunneling
A method of data exfiltration or command and control (C2) where malicious actors encapsulate data within DNS queries and responses, abusing legitimate DNS infrastructure to bypass firewalls and network security controls.
- Uses standard DNS ports (53/UDP, 53/TCP).
- Often characterized by unusually large DNS responses or specific subdomain patterns.
- Difficult to detect with traditional firewall rules due to legitimate protocol use.
Memory trick: Data can sneak out through many hidden doors.