CS0-003 Security Operations Practice Question
A security analyst is investigating a potential DNS tunneling attack. Which of the following patterns in DNS logs would most likely indicate such activity?
⚠ Common exam trap
CS0-004 often tests the distinction between generic suspicious DNS behaviors (NXDOMAIN floods, new domains) and the specific encoding-plus-frequency signature that uniquely identifies DNS tunneling, so candidates who pick 'new domain' or 'NXDOMAIN' miss the payload-carrying subdomain pattern.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Unusually long subdomain names with high query frequency to a single domain
DNS tunneling exfiltrates data or establishes command-and-control by encoding payloads into DNS query names, typically subdomains of an attacker-controlled domain. This produces unusually long subdomain labels (often near the 63-character label limit or 253-character FQDN limit) combined with high query volume to a single domain, because each query carries a chunk of encoded data. Option B captures both the encoding artifact (long names) and the beaconing pattern (high frequency to one domain) that together are the hallmark of tunneling tools like iodine, dnscat2, or DNSExfiltrator.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A high number of NXDOMAIN responses
Why it's wrong here
A high volume of NXDOMAIN (Non-Existent Domain) responses typically points to active network scanning, malware attempting domain generation algorithms (DGAs), or misconfigured internal applications. While highly suspicious, it indicates that the queried domains do not exist, whereas DNS tunneling relies on successful resolution to an attacker-controlled authoritative name server to exfiltrate data. Therefore, this is not a primary indicator of an active, successful DNS tunnel.
- ✓
Unusually long subdomain names with high query frequency to a single domain
Why this is correct
DNS tunneling utility tools encode payload data, such as commands or exfiltrated files, directly into the subdomain labels of a query destined for an attacker-controlled authoritative DNS server. Because of this encoding, the subdomains appear as long, high-entropy, randomized strings. A high frequency of these unique, lengthy queries directed to a single external domain is a definitive signature of active DNS tunneling.
- ✗
Consistent query intervals to a known legitimate domain
Why it's wrong here
Regular, predictable query intervals to a reputable, known legitimate domain are characteristic of command-and-control (C2) beaconing or routine software update checks rather than data exfiltration via DNS tunneling. DNS tunneling typically involves high-throughput, irregular, or rapid-fire queries designed to maximize data transfer rates. Furthermore, tunneling requires routing traffic through an attacker-controlled domain to decode the payloads, not a legitimate third-party domain.
- ✗
Queries to domains that are less than 24 hours old
Why it's wrong here
Newly registered domains (NRDs) that are less than 24 hours old represent a significant security risk often associated with phishing campaigns, spam, or fresh C2 infrastructure. However, the age of a domain alone does not indicate the specific protocol abuse of DNS tunneling, which is defined by its payload delivery mechanism rather than domain registration telemetry. Analysts must look for structural query anomalies rather than just domain age to confirm tunneling.
Visual reference
Go deeper
Related to this question
About these practice questions
This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.