nerdexam
EC-Council

312-85 · Question #29

An attacker instructs bots to use camouflage mechanism to hide his phishing and malware delivery locations in the rapidly changing network of compromised bots. In this particular technique, a single…

The correct answer is D. Fast-Flux DNS. Fast-Flux DNS (D) is correct because it's a technique where a single domain name rapidly cycles through many IP addresses (often hundreds of compromised bot IPs), with very short TTL values. This makes it extremely difficult to block or take down phishing/malware infrastructure…

Threat Intelligence Analysis

Question

An attacker instructs bots to use camouflage mechanism to hide his phishing and malware delivery locations in the rapidly changing network of compromised bots. In this particular technique, a single domain name consists of multiple IP addresses. Which of the following technique is used by the attacker?

Options

  • ADNS zone transfer
  • BDynamic DNS
  • CDNS interrogation
  • DFast-Flux DNS

How the community answered

(62 responses)
  • A
    6% (4)
  • B
    3% (2)
  • C
    2% (1)
  • D
    89% (55)

Explanation

Fast-Flux DNS (D) is correct because it's a technique where a single domain name rapidly cycles through many IP addresses (often hundreds of compromised bot IPs), with very short TTL values. This makes it extremely difficult to block or take down phishing/malware infrastructure - by the time you block one IP, the domain is already pointing elsewhere.

Why the distractors are wrong:

  • A. DNS zone transfer is a legitimate administrative process where a DNS server replicates its records to another server - it's a recon/enumeration vulnerability, not a camouflage technique.
  • B. Dynamic DNS allows a hostname to update its IP address automatically (e.g., for home servers with changing IPs), but it maps one domain to one changing IP, not one domain to many IPs simultaneously for evasion.
  • C. DNS interrogation refers to querying DNS servers to gather information about a target network - it's an attacker recon technique, not a hiding/camouflage mechanism.

Memory tip: Think "fast flux = fast-changing flux of IPs." Like a strobe light - the attacker's domain flickers through dozens of bot IPs so fast that blocklists can never catch up. If the question mentions botnets + multiple IPs + camouflage, the answer is almost always Fast-Flux DNS.

Topics

#Fast-Flux DNS#DNS evasion#Botnet C&C#Malware infrastructure

Community Discussion

No community discussion yet for this question.

Full 312-85 Practice