Cisco CyberOps Associate (CBROPS) 200-201Network Intrusion AnalysisHard

A security analyst is investigating a compromised Linux server. They discover persistent outbound connections to an external IP address on TCP port 53. Upon analysis of the packet payload, they find that the data within the DNS queries and responses is highly unusual, containing long, encoded strings that do not resemble legitimate domain names or DNS records, but rather base64 encoded data. What type of covert communication channel is being used?

  1. AHTTP tunneling
  2. BICMP tunneling
  3. CDNS tunneling
  4. DSSH tunneling
Show answer & explanation

Correct answer: C. DNS tunneling

DNS tunneling is a technique where attackers encapsulate other protocols' traffic (like TCP, SSH, or arbitrary data) within DNS queries and responses. The use of TCP port 53 (DNS port) for persistent outbound connections, combined with unusual, long, encoded strings within the DNS query/response payloads, are definitive indicators of DNS tunneling, often used for data exfiltration or command and control.

Why the other options are wrong

  • A. HTTP tunneling uses HTTP (ports 80/443) to encapsulate traffic, not DNS (port 53) with encoded strings in DNS queries.
  • B. ICMP tunneling uses ICMP packets to encapsulate data, not DNS queries on port 53.
  • D. SSH tunneling uses SSH (typically port 22) to create an encrypted tunnel, not DNS queries on port 53.

DNS Tunneling

A method of covert communication that encapsulates other protocols' traffic (like TCP or SSH) or arbitrary data within DNS queries and responses to bypass firewalls and network security controls.

  • Often used for command and control (C2) or data exfiltration.
  • Leverages the fact that DNS traffic is often allowed outbound.
  • Characterized by unusual, long, or malformed domain names/DNS records containing encoded data.

Memory trick: Covert channels are secret messages in plain sight.

More Network Intrusion Analysis questions