CompTIA CySA+ (CS0-003)Reporting and CommunicationHard
A security analyst is investigating a potential data exfiltration event that originated from an internal server. The analyst suspects a sophisticated attacker utilized DNS tunneling to covertly transfer data. Which of the following network indicators, observed in DNS logs, would provide the STRONGEST evidence of DNS tunneling exfiltration?
- AConsistent PTR record queries for internal IP addresses
- BRepeated queries for non-existent subdomains with unusually long, encoded strings
- CHigh volume of legitimate A record queries for public websites
- DIncreased NXDOMAIN responses from external DNS servers
Show answer & explanationAnswer & explanation
Correct answer: B. Repeated queries for non-existent subdomains with unusually long, encoded strings
DNS tunneling often involves encoding data within subdomains of legitimate-looking but non-existent domains. Repeated queries for these unusually long, encoded strings, resulting in NXDOMAIN responses (or CNAMEs for data retrieval), are a classic and strong indicator of DNS tunneling for data exfiltration.
Why the other options are wrong
- A. PTR record queries are for reverse DNS lookups, which is normal network behavior.
- C. This indicates normal web browsing, not malicious activity.
- D. While NXDOMAIN responses can occur, it's the 'repeated queries for non-existent subdomains with unusually long, encoded strings' that makes it strong evidence of tunneling, not just increased NXDOMAINs generally.
DNS Tunneling Indicators
Specific patterns in DNS traffic that suggest data is being covertly exfiltrated or command-and-control communications are occurring by encoding information within DNS queries and responses.
- Unusually long or malformed DNS queries.
- Queries for non-existent or suspicious subdomains.
- High volume of DNS traffic to specific external domains.
- Data encoded in query names or TXT records.
Memory trick: DNS Tunneling: 'Long, Encoded, NXDOMAIN' queries are the secret path.