Courseiva
Security Operations →mediumMultiple Choice

CAS-004 Security Operations Practice Question

A security analyst is monitoring network traffic and observes a high volume of DNS queries for randomly generated domain names that return NXDOMAIN responses. The queries originate from a single workstation and occur at regular intervals. Which of the following is the MOST likely explanation for this activity?

⚠ Common exam trap

A common mix-up: candidates confuse DGA activity with DNS tunneling, as both involve DNS but have different traffic patterns and purposes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A domain generation algorithm (DGA) used by malware for command and control

The scenario describes a workstation making repeated DNS queries for random domain names that do not resolve. This behavior is a hallmark of a domain generation algorithm (DGA) used by malware to locate its command-and-control server. DGAs generate many domain names, and the malware attempts to resolve them until one succeeds. The regular intervals and NXDOMAIN responses are typical of this technique.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    DNS tunneling for data exfiltration

    Why it's wrong here

    DNS tunneling typically involves encoding data within DNS queries and responses to exfiltrate information or establish command-and-control channels. It would not generate a high volume of NXDOMAIN responses because the attacker would set up authoritative DNS servers to respond to the queries. The regular intervals and random domain names are more indicative of a domain generation algorithm used by malware.

  • ✓

    A domain generation algorithm (DGA) used by malware for command and control

    Why this is correct

    A DGA is a technique used by malware to generate a large number of pseudo-random domain names to avoid detection and disruption of command-and-control (C2) servers. The malware attempts to resolve these domains until one resolves to an active C2 server. The high volume of NXDOMAIN responses and regular intervals are characteristic of DGA activity, as the malware periodically tries to contact its C2 infrastructure.

  • ✗

    A network scan using DNS enumeration techniques

    Why it's wrong here

    DNS enumeration typically involves querying for specific records (e.g., A, MX, TXT) of a target domain to gather information. It would not generate a large number of random domain names. Enumeration is usually targeted and may produce some NXDOMAIN responses, but not at regular intervals and with random names. This pattern is more consistent with automated malware behavior.

  • ✗

    A misconfigured DNS server causing excessive recursive lookups

    Why it's wrong here

    A misconfigured DNS server might cause excessive lookups, but it would not generate random domain names. Misconfigurations typically result in repeated queries for the same domain or timeouts. The random nature of the domains and the regular intervals strongly suggest a DGA rather than a simple misconfiguration. Additionally, the queries originate from a single workstation, not the DNS server itself.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.