Courseiva
Security Operations →hardMultiple Choice

CS0-003 Security Operations Practice Question

A security analyst uses Wireshark to capture traffic and notices an unusually high number of DNS queries for random-looking subdomains under a single domain, such as 'a1b2c3.malicious.com'. The TTL values are very low. The analyst suspects DNS tunneling. Which of the following additional indicators would most strongly support this hypothesis?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

DNS queries with unusually large TXT record response sizes

DNS tunneling often uses TXT records to encode data, and the packet sizes can be larger than normal DNS queries.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Large number of NXDOMAIN responses

    Why it's wrong here

    A high volume of NXDOMAIN (Non-Existent Domain) responses typically points to Domain Generation Algorithms (DGAs) used by malware for command-and-control discovery, or active network scanning. While suspicious, this pattern indicates that the queried domains do not exist, whereas active DNS tunneling relies on successful resolution to established, attacker-controlled authoritative name servers to exfiltrate data.

  • ✓

    DNS queries with unusually large TXT record response sizes

    Why this is correct

    DNS tunneling protocols frequently abuse TXT records because they can carry arbitrary, unstructured text payloads up to 65,535 bytes in size. When an analyst observes unusually large TXT record responses, it strongly indicates that an external server is sending encapsulated payload data or command-and-control instructions back to a compromised internal host.

  • ✗

    High number of A record queries

    Why it's wrong here

    Standard IPv4 address resolutions rely on A records, making a high volume of these queries common in normal network environments or during web-browsing spikes. Because A records only return 32-bit IP addresses, they are highly inefficient for downstream data transfer in tunneling operations, which favor TXT, NULL, or CNAME records to maximize payload capacity.

  • ✗

    Queries originating from a DNS server

    Why it's wrong here

    Internal DNS servers naturally generate a massive volume of outbound queries as they perform recursive lookups on behalf of client endpoints. Observing queries originating from a DNS server is standard behavior; instead, analysts look for anomalous endpoint-to-resolver traffic or direct external DNS queries from non-DNS assets to identify tunneling attempts.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.