mediumMultiple Choice
CAS-004 Practice Question: A threat hunter hypothesizes that a sophisticated…
A threat hunter hypothesizes that a sophisticated attacker is using DNS tunneling for command and control. Which data source would most likely confirm this activity?
⚠ Common exam trap
The trap is assuming network flow data is sufficient because it shows DNS traffic volume, when only DNS query logs contain the encoded payload needed to confirm tunneling.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
DNS query logs from authoritative/internal DNS servers
DNS tunneling encodes command-and-control data inside DNS queries and responses, so the authoritative or internal DNS server logs are the only data source that captures the full query strings, TXT/NULL record payloads, and response sizes needed to confirm the activity. These logs reveal anomalies such as unusually long subdomain labels, high-entropy hostnames, and excessive query volume to a single domain.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Network flow data (NetFlow)
Why it's wrong here
NetFlow records connection metadata such as source, destination, port and byte counts, but not DNS query names or payload content. It could hint at large transfers to an unusual resolver, yet confirming tunnelling requires DNS query logs showing encoded subdomains.
- ✓
DNS query logs from authoritative/internal DNS servers
Why this is correct
DNS query logs capture the full request-and-response traffic tunnelling relies on, including the long, high-entropy subdomains and unusual record types (TXT, NULL) that encode exfiltrated data and C2 instructions. This directly satisfies the stem's requirement to confirm DNS tunnelling, since endpoint or flow data alone cannot reveal the encoded payload contents.
- ✗
Endpoint antivirus alerts
Why it's wrong here
Endpoint antivirus alerts trigger on file, process and memory indicators, not on the content or volume of DNS queries leaving the host. They would confirm malware execution on an endpoint, whereas DNS tunnelling is confirmed by anomalous query patterns in DNS logs.
- ✗
Web proxy logs
Why it's wrong here
Web proxy logs record HTTP and HTTPS requests, so tunnelled DNS queries sent directly to a resolver never appear there. They would confirm exfiltration over web protocols, but DNS tunnelling is identified through query-level records such as DNS server logs or Zeek DNS logs.
Visual reference
Go deeper
Related to this question
About these practice questions
This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.