Cisco CyberOps Associate (CBROPS) 200-201Security MonitoringMedium

A security analyst is reviewing NetFlow records for a critical database server and notices a high volume of outbound UDP traffic on port 53 to external, non-authoritative DNS servers. The traffic pattern shows small, frequent queries and large, fragmented responses. What type of data exfiltration technique is most likely occurring?

  1. ASSH tunneling
  2. BICMP tunneling
  3. CHTTP tunneling
  4. DDNS tunneling
Show answer & explanation

Correct answer: D. DNS tunneling

DNS tunneling involves encapsulating data within DNS queries and responses to bypass firewalls and intrusion detection systems. The observation of high volume outbound UDP port 53 traffic, small queries, and large, fragmented responses is a strong indicator of this technique.

Why the other options are wrong

  • A. SSH tunneling uses SSH protocol (TCP 22) to create an encrypted tunnel, not UDP 53.
  • B. ICMP tunneling encapsulates data within ICMP echo requests and replies, not UDP 53.
  • C. HTTP tunneling uses HTTP/HTTPS traffic, typically on ports 80/443, not UDP 53.

DNS Tunneling

A method of data exfiltration or command-and-control communication that encodes data within DNS queries and responses to bypass security controls.

  • Uses UDP port 53, often to non-authoritative DNS servers.
  • Characterized by small queries and potentially large, fragmented responses.
  • Can be used for C2, data exfiltration, or bypassing firewalls.

Memory trick: Secret data slipping out through unexpected channels.

More Security Monitoring questions