nerdexam
CompTIA

PT0-003 · Question #155

A penetration tester is attempting to exfiltrate sensitive data from a client environment without alerting the client's blue team. Which of the following exfiltration methods most likely remain undete

The correct answer is C. Domain Name System. The Domain Name System (DNS) is commonly used for covert exfiltration because it is an essential protocol in most networks and is less likely to be scrutinized compared to other Data is encoded into DNS queries or responses, such as using subdomain fields to transmit sensitive in

Submitted by miguelv· Mar 6, 2026Post-exploitation and Lateral Movement

Question

A penetration tester is attempting to exfiltrate sensitive data from a client environment without alerting the client's blue team. Which of the following exfiltration methods most likely remain undetected?

Options

  • ACloud storage
  • BEmail
  • CDomain Name System
  • DTest storage sites

How the community answered

(47 responses)
  • A
    6% (3)
  • B
    4% (2)
  • C
    77% (36)
  • D
    13% (6)

Explanation

The Domain Name System (DNS) is commonly used for covert exfiltration because it is an essential protocol in most networks and is less likely to be scrutinized compared to other Data is encoded into DNS queries or responses, such as using subdomain fields to transmit sensitive information. These queries are sent to a malicious DNS server controlled by the attacker, allowing data to bypass traditional detection mechanisms. Why It Remains Undetected: DNS traffic is frequently allowed and not as heavily monitored compared to other channels like Network security tools often prioritize operational DNS traffic, making detection of anomalies more challenging.

Topics

#data exfiltration#DNS exfiltration#covert channels

Community Discussion

No community discussion yet for this question.

Full PT0-003 Practice