Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Network SecurityHard

A security incident response team is analyzing logs following a suspected data exfiltration event. They observe unusual outbound connections from an internal server to an unknown external IP address on TCP port 53. Which network service is typically associated with TCP port 53, and why might this be suspicious?

  1. ASMTP; it's suspicious because SMTP typically uses port 25.
  2. BFTP; it's suspicious because FTP uses ports 20 and 21.
  3. CDNS; it's suspicious because DNS queries typically use UDP port 53.
  4. DHTTP; it's suspicious because HTTP usually uses port 80 or 443.
Show answer & explanation

Correct answer: C. DNS; it's suspicious because DNS queries typically use UDP port 53.

TCP port 53 is associated with DNS, primarily for zone transfers. However, typical DNS queries use UDP port 53. Unusual outbound connections on TCP port 53 to an unknown external IP can indicate DNS tunneling, a method for data exfiltration.

Why the other options are wrong

  • A. SMTP uses TCP port 25, not 53.
  • B. FTP uses TCP ports 20/21, not 53.
  • D. HTTP uses TCP ports 80/443, not 53.

DNS Tunneling

A cyberattack method that encodes data of other programs or protocols inside DNS queries and responses, allowing attackers to bypass firewalls and exfiltrate data or establish command and control channels.

  • Leverages the DNS protocol, typically over TCP port 53 for zone transfers or UDP port 53 for queries.
  • Often used for data exfiltration or C2 communications.
  • Difficult to detect by traditional firewalls as DNS traffic is usually allowed.
  • Requires deep packet inspection or DNS anomaly detection for effective mitigation.

Memory trick: Normal protocols are like standard mail, but DNS tunneling is like sending secret messages hidden inside the address labels of seemingly normal letters.

More Network Security questions