Courseiva
Security →hardMultiple Choice

220-1102 Security Practice Question

A security analyst discovers that a malicious actor has been exfiltrating data from a company's internal network by encoding the stolen data into DNS queries sent to an external domain. Which type of attack is this?

⚠ Common exam trap

Test-takers frequently confuse DNS tunneling with DNS poisoning because both involve DNS, but the key distinction is that tunneling uses DNS as a covert channel for data transfer, while poisoning corrupts DNS resolution data to redirect traffic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

DNS tunneling

DNS tunneling is the correct answer because the attacker is encoding stolen data into DNS queries sent to an external domain, which is the hallmark of this technique. By encapsulating non-DNS traffic (e.g., exfiltrated data) within DNS packets, the attacker bypasses network security controls that typically allow DNS traffic outbound. This method exploits the fact that DNS is often unfiltered or minimally inspected, enabling covert data exfiltration.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    DNS poisoning

    Why it's wrong here

    DNS poisoning, or cache poisoning, corrupts a DNS resolver's cache by injecting forged DNS responses, causing users to be directed to malicious IP addresses. While this compromises the integrity of name resolution, it does not involve the covert extraction of data embedded within DNS queries or responses. The threat in this scenario is exfiltration, not redirecting victims, making DNS poisoning an incorrect answer.

  • ✓

    DNS tunneling

    Why this is correct

    DNS tunneling is a technique where an attacker embeds data into the payload of DNS queries and responses, often using subdomains or TXT records, and then parses that data from a rogue authoritative server. This allows covert command-and-control traffic or file exfiltration to pass through firewalls because DNS is generally permitted outbound. Since the scenario explicitly involves a malicious actor using DNS to move data, this matches perfectly as the correct answer.

  • ✗

    DNS hijacking

    Why it's wrong here

    DNS hijacking involves an attacker redirecting a victim's DNS queries to a rogue resolver, often achieved by modifying router settings, exploiting a domain registrar, or installing a malicious VPN. Its primary purpose is to intercept or block legitimate traffic, typically for phishing or credential theft, not to extract sensitive data by tunneling it out of the network. Unlike the described exfiltration, the attacker in a hijack controls the resolution path rather than hiding data inside DNS message fields.

  • ✗

    DNS amplification

    Why it's wrong here

    DNS amplification is a reflection-based distributed denial-of-service attack in which an attacker sends a large number of DNS queries with a spoofed source IP address, causing open resolvers to respond with large responses to the victim. The goal is to saturate the victim's bandwidth with traffic, rendering services unavailable, rather than to silently transfer data. Exfiltration requires a targeted, low-and-slow channel, not a high-volume flood, so this option does not fit the scenario.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

Go deeper

Related to this question

About these practice questions

Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.