Cisco CCNP Security Core (SCOR) 350-701Network SecurityEasy
A security operations center (SOC) analyst observes unusual outbound DNS queries from several internal hosts to an external, unclassified domain. The queries are frequent and appear to be encoding small chunks of data within the query names. What type of attack is most likely occurring?
- ADistributed Denial of Service (DDoS)
- BSQL Injection
- CCross-Site Scripting (XSS)
- DDNS Tunneling
Show answer & explanationAnswer & explanation
Correct answer: D. DNS Tunneling
DNS tunneling is a technique that encodes data of other programs or protocols in DNS queries and responses. This allows attackers to bypass firewalls and exfiltrate data by using the DNS protocol as a covert communication channel.
Why the other options are wrong
- A. DDoS attacks aim to overwhelm a system with traffic, not to exfiltrate data through DNS queries.
- B. SQL Injection targets databases and manipulates database queries, not DNS traffic.
- C. XSS attacks inject malicious scripts into web pages, affecting user browsers, not internal host DNS traffic for data exfiltration.
DNS Tunneling
A technique used to encapsulate data of other protocols inside DNS queries and responses, often for data exfiltration or command-and-control communication.
- Uses DNS protocol as a covert channel.
- Bypasses firewalls by leveraging allowed DNS traffic.
- Can be used for data exfiltration or C2 communications.
Memory trick: Remember the ghost whispering secrets through the network.