PT0-003 · Question #155
A penetration tester is attempting to exfiltrate sensitive data from a client environment without alerting the client's blue team. Which of the following exfiltration methods most likely remain undete
The correct answer is C. Domain Name System. The Domain Name System (DNS) is commonly used for covert exfiltration because it is an essential protocol in most networks and is less likely to be scrutinized compared to other Data is encoded into DNS queries or responses, such as using subdomain fields to transmit sensitive in
Question
A penetration tester is attempting to exfiltrate sensitive data from a client environment without alerting the client's blue team. Which of the following exfiltration methods most likely remain undetected?
Options
- ACloud storage
- BEmail
- CDomain Name System
- DTest storage sites
How the community answered
(47 responses)- A6% (3)
- B4% (2)
- C77% (36)
- D13% (6)
Explanation
The Domain Name System (DNS) is commonly used for covert exfiltration because it is an essential protocol in most networks and is less likely to be scrutinized compared to other Data is encoded into DNS queries or responses, such as using subdomain fields to transmit sensitive information. These queries are sent to a malicious DNS server controlled by the attacker, allowing data to bypass traditional detection mechanisms. Why It Remains Undetected: DNS traffic is frequently allowed and not as heavily monitored compared to other channels like Network security tools often prioritize operational DNS traffic, making detection of anomalies more challenging.
Topics
Community Discussion
No community discussion yet for this question.