Cisco CCNP Security Core (SCOR) 350-701Network SecurityHard

A security operations center (SOC) analyst observes a significant increase in DNS queries originating from multiple internal hosts to a large number of seemingly random, non-existent domains. This activity occurs in short bursts over several hours. What type of attack is this most indicative of?

  1. ADNS Tunneling
  2. BDNS Amplification
  3. CDNS Spoofing
  4. DDNS Exfiltration
Show answer & explanation

Correct answer: A. DNS Tunneling

DNS Tunneling involves encoding data within DNS queries and responses to create a covert communication channel, often seen as requests for many random, non-existent domains as data is fragmented and sent through DNS.

Why the other options are wrong

  • B. DNS amplification is a type of DDoS attack where attackers use open DNS resolvers to flood a target with traffic, not internal hosts querying random domains.
  • C. DNS spoofing involves providing fraudulent DNS responses to redirect users, not generating many random queries from internal hosts.
  • D. DNS exfiltration involves using DNS queries to extract data, which could involve random domains, but tunneling specifically refers to creating a covert channel, which is a broader and more accurate description of the activity.

DNS Tunneling

DNS tunneling is a technique that encapsulates data of other protocols (like IP) within DNS queries and responses, creating a covert communication channel that can bypass firewalls and security controls.

  • Used for command and control (C2) or data exfiltration.
  • Often characterized by high volumes of queries to non-existent or arbitrary subdomains.
  • Difficult to detect with traditional network security tools.

Memory trick: Tunneling: DNS queries are secret tunnels for data.

More Network Security questions