Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Network SecurityMedium
A security administrator is reviewing network traffic logs and observes a high volume of DNS queries for unusual, randomly generated subdomains, often followed by small amounts of data being sent to external IP addresses. This pattern is concerning because it suggests a covert communication channel. What type of attack or exfiltration technique is likely being observed?
- ADNS Tunneling
- BSQL Injection
- CCross-Site Scripting (XSS)
- DDenial of Service (DoS)
Show answer & explanationAnswer & explanation
Correct answer: A. DNS Tunneling
DNS tunneling involves encoding data within DNS queries and responses to establish a covert communication channel, often used for data exfiltration or command and control, matching the described observation of unusual DNS queries with data transfer.
Why the other options are wrong
- B. SQL Injection targets databases and manipulates queries, not typically involving unusual DNS traffic.
- C. XSS injects malicious scripts into websites to affect users, unrelated to DNS traffic anomalies.
- D. DoS attacks aim to disrupt service availability, usually with overwhelming traffic, not covert data transfer via DNS.
DNS Tunneling
A technique that abuses the DNS protocol to create a covert communication channel, often used to bypass firewalls or exfiltrate data.
- Encodes data within DNS queries and responses.
- Can be used for command and control or data exfiltration.
- Often difficult to detect by traditional firewalls as DNS traffic is usually allowed.
Memory trick: DNS Tunnel: Data hidden in plain sight, through the DNS road.