CAS-004 Security Operations Practice Question
A security analyst is investigating a suspected data exfiltration incident. The analyst has captured network traffic and wants to identify evidence of data being transferred over a covert channel. Which TWO of the following techniques would BEST help detect covert channels in the network traffic? (Choose two.)
⚠ Common exam trap
The trap here is focusing on volume-based anomalies or open ports, which may indicate exfiltration but fail to detect covert channels that hide within allowed protocols using encoding or tunneling.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Analyze DNS query patterns for unusually long or high-entropy subdomains.
Covert channels often hide data within protocols that are typically allowed through firewalls, such as DNS and ICMP. Analyzing DNS for long, high-entropy subdomains can reveal DNS tunneling, while inspecting ICMP payloads for anomalies can detect ICMP tunneling. Both techniques focus on the content and patterns within these protocols, which is essential for identifying stealthy exfiltration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Analyze DNS query patterns for unusually long or high-entropy subdomains.
Why this is correct
DNS tunneling often encodes data in subdomains, resulting in long, high-entropy labels. Analyzing DNS query patterns for these anomalies can reveal covert channels that bypass traditional perimeter controls. This technique is effective because DNS is frequently allowed outbound, and attackers abuse it to exfiltrate data or maintain C2. Monitoring for statistical anomalies in DNS queries is a key detection method.
- ✓
Inspect ICMP packets for unusual payload sizes or patterns.
Why this is correct
ICMP tunneling can embed data in echo request/reply payloads. Legitimate ICMP packets typically have small, predictable payloads (e.g., 32 bytes for ping). Unusual payload sizes, high entropy, or consistent large packets may indicate a covert channel. Inspecting ICMP for such anomalies helps detect this less common but effective exfiltration method.
- ✗
Scan internal hosts for open ports that could be used for data transfer.
Why it's wrong here
Port scanning identifies open ports but does not detect covert channels, which often use standard open ports like 53 or 80. Covert channels operate within allowed protocols, so open port scans would not reveal them. This action is more relevant to vulnerability management or attack surface reduction, not covert channel detection.
- ✗
Examine NetFlow records for spikes in outbound traffic volume during off-hours.
Why it's wrong here
NetFlow volume anomalies can indicate exfiltration but do not specifically detect covert channels, which may involve low-volume, stealthy transfers. Covert channels often avoid volume spikes to evade detection. NetFlow lacks payload inspection, so it cannot identify encoded data within protocols. Thus, it is less effective for detecting covert channels compared to payload analysis.
- ✗
Monitor for large file transfers over HTTP/HTTPS to known cloud storage services.
Why it's wrong here
While large transfers to cloud storage could indicate exfiltration, this is not a covert channel technique; it is overt and may be legitimate. Covert channels aim to hide data within protocols, not use obvious bulk transfer. This method may detect data exfiltration but not specifically covert channels, and it may generate many false positives from legitimate business use.
Go deeper
Related to this question
About these practice questions
One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.