Cisco CyberOps Associate (CBROPS) 200-201Network Intrusion AnalysisMedium

A security analyst is investigating a compromised workstation that was communicating with an external IP address over port 53. Further inspection of the packet capture reveals that the DNS queries are unusually long and contain seemingly random alphanumeric strings within the query name, often followed by a known malicious domain. The responses are also non-standard, containing encoded data. What type of covert communication channel is this likely indicative of?

  1. ASSH Tunneling
  2. BHTTP C2 Channel
  3. CDNS Tunneling
  4. DICMP Tunneling
Show answer & explanation

Correct answer: C. DNS Tunneling

The scenario describes communication over port 53 (DNS), unusually long DNS queries with random strings, and encoded data in responses. These are classic indicators of DNS tunneling, where data is exfiltrated or C2 commands are sent by embedding them within DNS query and response fields.

Why the other options are wrong

  • A. SSH tunneling typically uses port 22 and encrypts traffic, but the communication would be SSH protocol, not malformed DNS queries.
  • B. HTTP C2 channels use ports 80/443 and would involve HTTP protocol headers and methods, not DNS queries.
  • D. ICMP tunneling uses ICMP echo requests and replies (ping) to encapsulate data, not DNS traffic on port 53.

DNS Tunneling

A technique that encapsulates data of other protocols within DNS queries and responses to bypass firewalls and security controls.

  • Uses port 53 (DNS).
  • Often involves long, unusual DNS queries containing encoded data.
  • Can be used for command and control (C2) or data exfiltration.

Memory trick: DNS hides secrets, like a submarine in plain sight, using its own network for a new mission.

More Network Intrusion Analysis questions