200-201 · Question #471
Refer to the exhibit. A network engineer received a report that a host is communicating with unknown domains on the internet. The network engineer collected packet capture but could not determine…
The correct answer is D. tunneling. The presence of the prefix dnscat in all queries strongly suggests that this is related to DNSCat or DNSCat2, which are tools commonly used for DNS tunneling. DNS tunneling involves encoding data into DNS queries and responses to establish a covert communication channel. This…
Question
Refer to the exhibit. A network engineer received a report that a host is communicating with unknown domains on the internet. The network engineer collected packet capture but could not determine the technique or the payload used. What technique is the attacker using?
Exhibit
Options
- Ateardrop
- Bamplification
- Csession hijacking
- Dtunneling
How the community answered
(64 responses)- A5% (3)
- B3% (2)
- C13% (8)
- D80% (51)
Explanation
The presence of the prefix dnscat in all queries strongly suggests that this is related to DNSCat or DNSCat2, which are tools commonly used for DNS tunneling. DNS tunneling involves encoding data into DNS queries and responses to establish a covert communication channel. This can be used for exfiltrating data or for maintaining a backdoor communication channel to the network, bypassing traditional firewall rules since DNS is often allowed through most firewalls. The types of records queried (TXT, CNAME, MX) are commonly used for tunneling because they can store arbitrary data, making it easier to encode and transmit information within these DNS Teardrop refers to a denial-of-service attack that sends fragmented packets, not relevant here. Amplification is a form of DDoS attack using large responses to small queries, which is not Session hijacking involves taking over an existing session, which does not match the observed traffic pattern in this exhibit.
Topics
Community Discussion
No community discussion yet for this question.
