Cisco CyberOps Associate (CBROPS) 200-201Security ConceptsEasy
A security analyst is investigating a series of alerts indicating unusual outbound traffic from a web server. The alerts show connections being established to various external IP addresses on TCP port 53. The web server should only be communicating with internal DNS resolvers. Which common attack vector is most likely being exploited?
- ADenial of Service (DoS)
- BDNS Tunneling
- CSQL Injection
- DCross-Site Scripting (XSS)
Show answer & explanationAnswer & explanation
Correct answer: B. DNS Tunneling
DNS tunneling is a technique that can be used to exfiltrate data or establish command and control channels by encoding data within DNS queries and responses. The use of TCP port 53 for unusual outbound traffic, especially from a web server that should only use internal DNS, strongly suggests this attack vector.
Why the other options are wrong
- A. Denial of Service (DoS) attacks aim to make a service unavailable and do not typically involve a web server initiating unusual outbound DNS connections for data exfiltration.
- C. SQL Injection exploits database vulnerabilities and typically involves web application input, not unusual outbound DNS traffic.
- D. Cross-Site Scripting (XSS) is a client-side attack that injects malicious scripts into web pages, not related to outbound DNS traffic from a server.
DNS Tunneling
A cyberattack method that encodes data of other programs or protocols in DNS queries and responses, often used for data exfiltration or command-and-control communication.
- Uses DNS protocol (port 53) to bypass firewalls.
- Can be used for data exfiltration, command and control, or bypassing network restrictions.
- Often involves unusual DNS query patterns or large response sizes.
Memory trick: DNS Tunnels: Data Sneaks Out Silently.