Courseiva
Security Operations →mediumMultiple Choice

CS0-003 Security Operations Practice Question

A security analyst is investigating a potential DNS tunneling attack. Which of the following patterns in DNS logs would most likely indicate such activity?

⚠ Common exam trap

CS0-004 often tests the distinction between generic suspicious DNS behaviors (NXDOMAIN floods, new domains) and the specific encoding-plus-frequency signature that uniquely identifies DNS tunneling, so candidates who pick 'new domain' or 'NXDOMAIN' miss the payload-carrying subdomain pattern.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Unusually long subdomain names with high query frequency to a single domain

DNS tunneling exfiltrates data or establishes command-and-control by encoding payloads into DNS query names, typically subdomains of an attacker-controlled domain. This produces unusually long subdomain labels (often near the 63-character label limit or 253-character FQDN limit) combined with high query volume to a single domain, because each query carries a chunk of encoded data. Option B captures both the encoding artifact (long names) and the beaconing pattern (high frequency to one domain) that together are the hallmark of tunneling tools like iodine, dnscat2, or DNSExfiltrator.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A high number of NXDOMAIN responses

    Why it's wrong here

    A high volume of NXDOMAIN (Non-Existent Domain) responses typically points to active network scanning, malware attempting domain generation algorithms (DGAs), or misconfigured internal applications. While highly suspicious, it indicates that the queried domains do not exist, whereas DNS tunneling relies on successful resolution to an attacker-controlled authoritative name server to exfiltrate data. Therefore, this is not a primary indicator of an active, successful DNS tunnel.

  • ✓

    Unusually long subdomain names with high query frequency to a single domain

    Why this is correct

    DNS tunneling utility tools encode payload data, such as commands or exfiltrated files, directly into the subdomain labels of a query destined for an attacker-controlled authoritative DNS server. Because of this encoding, the subdomains appear as long, high-entropy, randomized strings. A high frequency of these unique, lengthy queries directed to a single external domain is a definitive signature of active DNS tunneling.

  • ✗

    Consistent query intervals to a known legitimate domain

    Why it's wrong here

    Regular, predictable query intervals to a reputable, known legitimate domain are characteristic of command-and-control (C2) beaconing or routine software update checks rather than data exfiltration via DNS tunneling. DNS tunneling typically involves high-throughput, irregular, or rapid-fire queries designed to maximize data transfer rates. Furthermore, tunneling requires routing traffic through an attacker-controlled domain to decode the payloads, not a legitimate third-party domain.

  • ✗

    Queries to domains that are less than 24 hours old

    Why it's wrong here

    Newly registered domains (NRDs) that are less than 24 hours old represent a significant security risk often associated with phishing campaigns, spam, or fresh C2 infrastructure. However, the age of a domain alone does not indicate the specific protocol abuse of DNS tunneling, which is defined by its payload delivery mechanism rather than domain registration telemetry. Analysts must look for structural query anomalies rather than just domain age to confirm tunneling.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.