CAS-004 Security Operations Practice Question
A security analyst is investigating a suspected DNS tunneling attack. The analyst observes a high volume of DNS queries to a single domain, with query names that appear to be Base64-encoded strings. Which of the following is the MOST effective way to confirm and analyze this activity?
⚠ Common exam trap
The trap here is focusing on network-level indicators like IP reputation or response times instead of examining the actual DNS payload for encoded data.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Capture full packet data and decode the query names to look for hidden data
DNS tunneling hides data within DNS queries and responses. To confirm and analyze it, the analyst must capture the actual DNS packets and decode the query names, which often contain Base64 or hex-encoded payloads. This reveals the exfiltrated data or C2 commands. The other options may provide circumstantial evidence but do not directly analyze the tunneled content.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Capture full packet data and decode the query names to look for hidden data
Why this is correct
DNS tunneling encodes data in DNS query names or responses. Capturing full packets allows the analyst to extract the query strings, decode them (e.g., Base64), and examine the payload. This confirms tunneling and reveals exfiltrated or command-and-control data. Other methods may indicate tunneling but do not provide the actual content for analysis.
- ✗
Check the reputation of the destination DNS server IP address
Why it's wrong here
Checking the reputation of the DNS server IP can indicate if it is known malicious, but it does not confirm tunneling or reveal the data being transmitted. Attackers often use compromised or legitimate DNS servers, so reputation alone is insufficient. The scenario requires analyzing the encoded query names, which this method does not address.
- ✗
Monitor for an increase in DNS response time
Why it's wrong here
Increased DNS response time might indicate a misconfigured or overloaded DNS server, but it is not specific to tunneling. Tunneling can occur with normal response times if the server is efficient. This method does not provide the means to decode the query names or confirm the presence of hidden data.
- ✗
Review firewall logs for allowed outbound DNS traffic
Why it's wrong here
Firewall logs show whether DNS traffic is permitted, but they do not provide the query contents or allow decoding of the encoded strings. This might help identify the scope of the traffic, but it cannot confirm tunneling or analyze the payload. The question emphasizes the need to decode the query names.
Visual reference
About these practice questions
Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.