Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Network SecurityMedium

A security administrator is reviewing network traffic logs and observes a high volume of DNS queries for unusual, randomly generated subdomains, often followed by small amounts of data being sent to external IP addresses. This pattern is concerning because it suggests a covert communication channel. What type of attack or exfiltration technique is likely being observed?

  1. ADNS Tunneling
  2. BSQL Injection
  3. CCross-Site Scripting (XSS)
  4. DDenial of Service (DoS)
Show answer & explanation

Correct answer: A. DNS Tunneling

DNS tunneling involves encoding data within DNS queries and responses to establish a covert communication channel, often used for data exfiltration or command and control, matching the described observation of unusual DNS queries with data transfer.

Why the other options are wrong

  • B. SQL Injection targets databases and manipulates queries, not typically involving unusual DNS traffic.
  • C. XSS injects malicious scripts into websites to affect users, unrelated to DNS traffic anomalies.
  • D. DoS attacks aim to disrupt service availability, usually with overwhelming traffic, not covert data transfer via DNS.

DNS Tunneling

A technique that abuses the DNS protocol to create a covert communication channel, often used to bypass firewalls or exfiltrate data.

  • Encodes data within DNS queries and responses.
  • Can be used for command and control or data exfiltration.
  • Often difficult to detect by traditional firewalls as DNS traffic is usually allowed.

Memory trick: DNS Tunnel: Data hidden in plain sight, through the DNS road.

More Network Security questions