Courseiva
Security Operations →mediumMultiple Choice

CAS-004 Security Operations Practice Question

A security analyst is investigating a suspected DNS tunneling attack. The analyst observes a high volume of DNS queries to a single domain, with query names that appear to be Base64-encoded strings. Which of the following is the MOST effective way to confirm and analyze this activity?

⚠ Common exam trap

The trap here is focusing on network-level indicators like IP reputation or response times instead of examining the actual DNS payload for encoded data.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Capture full packet data and decode the query names to look for hidden data

DNS tunneling hides data within DNS queries and responses. To confirm and analyze it, the analyst must capture the actual DNS packets and decode the query names, which often contain Base64 or hex-encoded payloads. This reveals the exfiltrated data or C2 commands. The other options may provide circumstantial evidence but do not directly analyze the tunneled content.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Capture full packet data and decode the query names to look for hidden data

    Why this is correct

    DNS tunneling encodes data in DNS query names or responses. Capturing full packets allows the analyst to extract the query strings, decode them (e.g., Base64), and examine the payload. This confirms tunneling and reveals exfiltrated or command-and-control data. Other methods may indicate tunneling but do not provide the actual content for analysis.

  • ✗

    Check the reputation of the destination DNS server IP address

    Why it's wrong here

    Checking the reputation of the DNS server IP can indicate if it is known malicious, but it does not confirm tunneling or reveal the data being transmitted. Attackers often use compromised or legitimate DNS servers, so reputation alone is insufficient. The scenario requires analyzing the encoded query names, which this method does not address.

  • ✗

    Monitor for an increase in DNS response time

    Why it's wrong here

    Increased DNS response time might indicate a misconfigured or overloaded DNS server, but it is not specific to tunneling. Tunneling can occur with normal response times if the server is efficient. This method does not provide the means to decode the query names or confirm the presence of hidden data.

  • ✗

    Review firewall logs for allowed outbound DNS traffic

    Why it's wrong here

    Firewall logs show whether DNS traffic is permitted, but they do not provide the query contents or allow decoding of the encoded strings. This might help identify the scope of the traffic, but it cannot confirm tunneling or analyze the payload. The question emphasizes the need to decode the query names.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.