200-201 · Question #255
Refer to the exhibit. What is occurring?
The correct answer is D. DNS tunneling. DNS tunneling uses DNS queries and responses to covertly transmit non-DNS data, often by encoding it within subdomains or record types, appearing as unusual DNS traffic patterns.
Question
Refer to the exhibit. What is occurring?
Exhibit
Options
- AARP flood
- BDNS amplification
- CARP poisoning
- DDNS tunneling
How the community answered
(42 responses)- A5% (2)
- B7% (3)
- C17% (7)
- D71% (30)
Why each option
DNS tunneling uses DNS queries and responses to covertly transmit non-DNS data, often by encoding it within subdomains or record types, appearing as unusual DNS traffic patterns.
An ARP flood involves sending excessive ARP requests to overwhelm a network device, which would show an abundance of ARP traffic, not unusual DNS activity.
DNS amplification is a type of DDoS attack that abuses open DNS resolvers to magnify attack traffic, typically characterized by a large volume of small queries leading to large responses directed at a victim, distinct from covert data transfer within DNS itself.
ARP poisoning involves sending forged ARP messages to redirect traffic for man-in-the-middle attacks, appearing as forged ARP responses rather than unusual DNS activity.
DNS tunneling is a technique used to exfiltrate data or establish command and control (C2) channels by encoding arbitrary data within DNS queries and responses. An exhibit showing unusual or abnormally large DNS traffic, especially with suspicious subdomains or record types, would be indicative of this covert communication method.
Concept tested: DNS tunneling detection
Source: https://learn.microsoft.com/en-us/azure/azure-monitor/reference/threat-detection/dns-tunneling
Topics
Community Discussion
No community discussion yet for this question.
