Courseiva
Security Operations →mediumMultiple Choice

CS0-003 Security Operations Practice Question

A security analyst is investigating a potential data exfiltration incident. They notice a host sending large amounts of data to an external IP address using DNS queries. Which technique is most likely being used?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

DNS tunneling

DNS tunneling encodes data in DNS queries and responses, allowing exfiltration over port 53, which is often allowed through firewalls.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    DNS tunneling

    Why this is correct

    DNS tunneling abuses the DNS protocol to bypass network security controls by encoding exfiltrated data or command-and-control (C2) payloads within DNS queries and responses (such as TXT, CNAME, or MX records). Because firewalls typically allow unrestricted outbound UDP port 53 traffic to resolve domain names, attackers can establish a covert bidirectional communication channel to slowly leak sensitive information without triggering traditional perimeter defenses.

  • ✗

    DGA

    Why it's wrong here

    Domain Generation Algorithms (DGAs) are programmatically used by malware to dynamically generate a large number of pseudo-random domain names to locate active command-and-control (C2) servers. While DGAs help malware evade static domain blocking and maintain connection resilience, they are not a mechanism designed for the actual packaging and exfiltration of data payloads.

  • ✗

    HTTP smuggling

    Why it's wrong here

    HTTP request smuggling is an application-layer attack that exploits discrepancies in how a front-end proxy and a back-end web server interpret HTTP request boundaries, typically by manipulating the Content-Length and Transfer-Encoding headers. This technique allows attackers to bypass security controls, hijack user sessions, or access unauthorized APIs, but it does not utilize DNS queries or serve as a primary protocol-tunneling method for bulk data exfiltration.

  • ✗

    Beaconing

    Why it's wrong here

    Beaconing refers to the highly structured, periodic outbound signals sent by compromised hosts to a command-and-control (C2) server to announce their active status and check for pending instructions. These transmissions typically consist of minimal, low-volume packets designed to blend in with normal network traffic, making them distinct from the high-volume or continuous data payloads associated with active exfiltration.

About these practice questions

One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.