nerdexam
CompTIA

PT0-003 · Question #140

Which of the following protocols would a penetration tester most likely utilize to exfiltrate data covertly and evade detection?

The correct answer is D. DNS. DNS (Domain Name System) is often used for data exfiltration because it is a fundamental protocol that is usually allowed through firewalls and not scrutinized as heavily as others. By embedding data into DNS queries and responses, attackers can stealthily transmit information…

Submitted by tunde_lagos· Mar 6, 2026Post-exploitation and lateral movement

Question

Which of the following protocols would a penetration tester most likely utilize to exfiltrate data covertly and evade detection?

Options

  • AFTP
  • BHTTPS
  • CSMTP
  • DDNS

How the community answered

(25 responses)
  • A
    8% (2)
  • B
    4% (1)
  • D
    88% (22)

Explanation

DNS (Domain Name System) is often used for data exfiltration because it is a fundamental protocol that is usually allowed through firewalls and not scrutinized as heavily as others. By embedding data into DNS queries and responses, attackers can stealthily transmit information without raising immediate suspicion.

Topics

#Data exfiltration#Covert channels#DNS tunneling#Network protocols

Community Discussion

No community discussion yet for this question.

Full PT0-003 Practice