CS0-003 Security Operations Practice Question
A security analyst is investigating a potential data exfiltration incident. They notice a host sending large amounts of data to an external IP address using DNS queries. Which technique is most likely being used?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
DNS tunneling
DNS tunneling encodes data in DNS queries and responses, allowing exfiltration over port 53, which is often allowed through firewalls.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
DNS tunneling
Why this is correct
DNS tunneling abuses the DNS protocol to bypass network security controls by encoding exfiltrated data or command-and-control (C2) payloads within DNS queries and responses (such as TXT, CNAME, or MX records). Because firewalls typically allow unrestricted outbound UDP port 53 traffic to resolve domain names, attackers can establish a covert bidirectional communication channel to slowly leak sensitive information without triggering traditional perimeter defenses.
- ✗
DGA
Why it's wrong here
Domain Generation Algorithms (DGAs) are programmatically used by malware to dynamically generate a large number of pseudo-random domain names to locate active command-and-control (C2) servers. While DGAs help malware evade static domain blocking and maintain connection resilience, they are not a mechanism designed for the actual packaging and exfiltration of data payloads.
- ✗
HTTP smuggling
Why it's wrong here
HTTP request smuggling is an application-layer attack that exploits discrepancies in how a front-end proxy and a back-end web server interpret HTTP request boundaries, typically by manipulating the Content-Length and Transfer-Encoding headers. This technique allows attackers to bypass security controls, hijack user sessions, or access unauthorized APIs, but it does not utilize DNS queries or serve as a primary protocol-tunneling method for bulk data exfiltration.
- ✗
Beaconing
Why it's wrong here
Beaconing refers to the highly structured, periodic outbound signals sent by compromised hosts to a command-and-control (C2) server to announce their active status and check for pending instructions. These transmissions typically consist of minimal, low-volume packets designed to blend in with normal network traffic, making them distinct from the high-volume or continuous data payloads associated with active exfiltration.
Go deeper
Related to this question
Learn chapter
DDoS Attack Incident Response
Key term
Incident
An incident is a security event that violates an organization's policies or threatens its data, systems, or operations, requiring a structured response.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.