Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Network SecurityHard
A security analyst is reviewing network traffic logs and observes a high volume of seemingly legitimate DNS queries originating from internal hosts, but these queries are for unusual, non-existent domain names and contain encoded data. The destination DNS server is an external, non-standard server. What advanced persistent threat (APT) technique is most likely being employed by an attacker in this scenario?
- ACross-Site Scripting (XSS)
- BDNS Tunneling
- CSQL Injection
- DBrute-force attack
Show answer & explanationAnswer & explanation
Correct answer: B. DNS Tunneling
DNS tunneling is a technique used by attackers to exfiltrate data or establish command-and-control channels by encoding data within legitimate-looking DNS queries and responses. The 'unusual, non-existent domain names' and 'encoded data' are key indicators.
Why the other options are wrong
- A. XSS is a client-side web vulnerability, unrelated to DNS queries for C2.
- C. SQL Injection targets databases, not network communication channels using DNS.
- D. Brute-force attacks involve guessing credentials, not encoding data in DNS for C2.
DNS Tunneling
An attack method that uses the DNS protocol to tunnel data and commands between an attacker's server and a compromised client.
- Abuses DNS queries and responses to create a covert communication channel.
- Often used for data exfiltration or command and control (C2).
- Difficult to detect by traditional firewalls as DNS traffic is typically allowed.
Memory trick: Covert channels are like secret messages hidden in plain sight.