Cisco CyberOps Associate (CBROPS) 200-201Network Intrusion AnalysisMedium

A security analyst is reviewing a packet capture and observes numerous outbound UDP packets on port 53 (DNS) to an external DNS server, where the query names are unusually long, randomly generated strings, and the responses are similarly large. This behavior is originating from a compromised internal host. What type of covert channel or exfiltration technique does this most likely represent?

  1. AHTTP tunneling
  2. BICMP flood
  3. CSMTP relay abuse
  4. DDNS tunneling
Show answer & explanation

Correct answer: D. DNS tunneling

DNS tunneling involves encoding data within DNS queries and responses, often resulting in unusually long or randomized domain names and large DNS responses, making it a common method for C2 communication or data exfiltration.

Why the other options are wrong

  • A. HTTP tunneling uses TCP ports 80/443, not UDP port 53, and involves HTTP requests/responses.
  • B. An ICMP flood is a DoS attack using ICMP echo requests; it does not involve DNS queries or data encoding.
  • C. SMTP relay abuse uses email protocols (TCP 25/587) to send unsolicited mail, not DNS queries for data exfiltration.

DNS Tunneling

DNS tunneling is a cyber attack method that encodes data of other programs or protocols in DNS queries and responses. Attackers use it to bypass firewalls, exfiltrate data, or establish a command-and-control (C2) channel.

  • Uses UDP port 53 (DNS)
  • Encodes data within domain names or DNS records
  • Often characterized by unusually long, random, or frequent DNS queries
  • Can be used for C2 communication or data exfiltration

Memory trick: Covert channels are 'Secret Messages' hidden in plain sight.

More Network Intrusion Analysis questions