Cisco CCNP Security Core (SCOR) 350-701Network SecurityHard
A security operations center (SOC) analyst observes a significant increase in DNS queries originating from multiple internal hosts to a large number of seemingly random, non-existent domains. This activity occurs in short bursts over several hours. What type of attack is this most indicative of?
- ADNS Tunneling
- BDNS Amplification
- CDNS Spoofing
- DDNS Exfiltration
Show answer & explanationAnswer & explanation
Correct answer: A. DNS Tunneling
DNS Tunneling involves encoding data within DNS queries and responses to create a covert communication channel, often seen as requests for many random, non-existent domains as data is fragmented and sent through DNS.
Why the other options are wrong
- B. DNS amplification is a type of DDoS attack where attackers use open DNS resolvers to flood a target with traffic, not internal hosts querying random domains.
- C. DNS spoofing involves providing fraudulent DNS responses to redirect users, not generating many random queries from internal hosts.
- D. DNS exfiltration involves using DNS queries to extract data, which could involve random domains, but tunneling specifically refers to creating a covert channel, which is a broader and more accurate description of the activity.
DNS Tunneling
DNS tunneling is a technique that encapsulates data of other protocols (like IP) within DNS queries and responses, creating a covert communication channel that can bypass firewalls and security controls.
- Used for command and control (C2) or data exfiltration.
- Often characterized by high volumes of queries to non-existent or arbitrary subdomains.
- Difficult to detect with traditional network security tools.
Memory trick: Tunneling: DNS queries are secret tunnels for data.