Cisco CyberOps Associate (CBROPS) 200-201Security ConceptsMedium
A security analyst is investigating a series of anomalies on a corporate network. They observe that several internal hosts are making repeated outbound connections to a known malicious IP address on port 53, and the data exchanged appears to be disguised as DNS queries and responses. What type of attack is most likely occurring?
- ASQL Injection
- BDistributed Denial of Service (DDoS)
- CMan-in-the-Middle (MitM)
- DDNS Tunneling
Show answer & explanationAnswer & explanation
Correct answer: D. DNS Tunneling
DNS tunneling is a technique that encapsulates data of other programs or protocols within DNS queries and responses. This allows attackers to bypass firewalls and exfiltrate data or establish command and control channels by leveraging the DNS protocol, which is often allowed through firewalls.
Why the other options are wrong
- A. SQL Injection targets databases through web application input, not network traffic disguised as DNS.
- B. DDoS attacks aim to overwhelm a service with traffic, not to exfiltrate data via disguised DNS.
- C. MitM attacks intercept communication between two parties, but wouldn't typically involve disguising data as DNS queries for exfiltration.
DNS Tunneling
A cyberattack method that encodes data of other programs or protocols into DNS queries and responses. This technique is often used to bypass firewalls and security controls, exfiltrate data, or establish command and control (C2) channels.
- Uses DNS protocol to carry non-DNS traffic.
- Often used for data exfiltration or C2.
- Can bypass firewalls that allow DNS traffic.
Memory trick: DNS is like a secret tunnel for naughty data.