Cisco CyberOps Associate (CBROPS) 200-201Security MonitoringMedium
A security analyst is reviewing NetFlow records for a critical database server and notices a sudden, sustained increase in outbound traffic to an unfamiliar external IP address on port 53 (DNS). The traffic volume is significantly higher than typical DNS traffic for this server. What type of activity does this pattern most likely indicate?
- ALegitimate DNS query activity
- BSSH remote access
- CNTP time synchronization
- DDNS tunneling for data exfiltration
Show answer & explanationAnswer & explanation
Correct answer: D. DNS tunneling for data exfiltration
DNS tunneling is a technique used to encapsulate other protocols' traffic within DNS queries and responses. A sudden, sustained increase in outbound traffic on port 53 (DNS) to an unfamiliar external IP, especially if the volume is atypical for normal DNS, strongly suggests data exfiltration or command and control via DNS tunneling.
Why the other options are wrong
- A. Legitimate DNS queries are usually sporadic and have a much lower sustained volume, not a 'sudden, sustained increase' of 'significantly higher' volume.
- B. SSH (Secure Shell) operates on TCP port 22 and is for remote access, not typically associated with high-volume outbound traffic to unfamiliar IPs on port 53.
- C. NTP (Network Time Protocol) operates on UDP port 123, not port 53, and its traffic patterns are typically low volume.
DNS Tunneling
A technique that encodes the data of other programs or protocols inside DNS queries and responses, often used to bypass firewalls, exfiltrate data, or establish command and control (C2) channels.
- Uses DNS (port 53) as a covert communication channel.
- Can bypass traditional firewall rules that allow DNS traffic.
- Often characterized by abnormally high DNS traffic volume or unusual query patterns.
Memory trick: Hidden data, like a ghost, travels through unexpected routes.