Courseiva
mediumMultiple Choice

CAS-004 Practice Question: A threat hunter hypothesizes that a sophisticated…

A threat hunter hypothesizes that a sophisticated attacker is using DNS tunneling for command and control. Which data source would most likely confirm this activity?

⚠ Common exam trap

The trap is assuming network flow data is sufficient because it shows DNS traffic volume, when only DNS query logs contain the encoded payload needed to confirm tunneling.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

DNS query logs from authoritative/internal DNS servers

DNS tunneling encodes command-and-control data inside DNS queries and responses, so the authoritative or internal DNS server logs are the only data source that captures the full query strings, TXT/NULL record payloads, and response sizes needed to confirm the activity. These logs reveal anomalies such as unusually long subdomain labels, high-entropy hostnames, and excessive query volume to a single domain.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Network flow data (NetFlow)

    Why it's wrong here

    NetFlow records connection metadata such as source, destination, port and byte counts, but not DNS query names or payload content. It could hint at large transfers to an unusual resolver, yet confirming tunnelling requires DNS query logs showing encoded subdomains.

  • ✓

    DNS query logs from authoritative/internal DNS servers

    Why this is correct

    DNS query logs capture the full request-and-response traffic tunnelling relies on, including the long, high-entropy subdomains and unusual record types (TXT, NULL) that encode exfiltrated data and C2 instructions. This directly satisfies the stem's requirement to confirm DNS tunnelling, since endpoint or flow data alone cannot reveal the encoded payload contents.

  • ✗

    Endpoint antivirus alerts

    Why it's wrong here

    Endpoint antivirus alerts trigger on file, process and memory indicators, not on the content or volume of DNS queries leaving the host. They would confirm malware execution on an endpoint, whereas DNS tunnelling is confirmed by anomalous query patterns in DNS logs.

  • ✗

    Web proxy logs

    Why it's wrong here

    Web proxy logs record HTTP and HTTPS requests, so tunnelled DNS queries sent directly to a resolver never appear there. They would confirm exfiltration over web protocols, but DNS tunnelling is identified through query-level records such as DNS server logs or Zeek DNS logs.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.