hardMultiple Select
CS0-003 Practice Question: An analyst suspects DNS tunnelling but wants to…
An analyst suspects DNS tunnelling but wants to avoid over-escalating normal CDN behaviour. Which comparisons help? (Choose two.)
⚠ Common exam trap
Test-takers frequently confuse DNS tunnelling detection with generic anomaly detection, overlooking the need for a host-specific baseline to avoid flagging legitimate CDN traffic that naturally has higher query rates or longer subdomains.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Baseline query length, entropy, and subdomain uniqueness for the host
DNS tunnelling encodes non-DNS data (e.g., file exfiltration or C2 commands) into DNS queries, often producing abnormally long, high-entropy subdomains. Comparing current query length, entropy, and subdomain uniqueness against a baseline for the same host helps distinguish tunnelling from legitimate CDN traffic, which typically uses short, predictable subdomains. This approach focuses on the structural characteristics of the queries themselves, avoiding false positives from normal CDN behaviour.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Baseline query length, entropy, and subdomain uniqueness for the host
Why this is correct
Establishing a baseline of query length, Shannon entropy, and subdomain uniqueness allows analysts to detect the high-entropy, long, and highly unique subdomains typical of DNS tunneling payloads. Because DNS tunnels encode data such as SSH or VPN traffic within TXT, CNAME, or AAAA queries, these requests deviate significantly from a host's normal, structured DNS patterns. Monitoring these specific label characteristics helps identify exfiltration or command-and-control channels without generating excessive false positives.
- ✓
Compare query rate and destination domains against peer hosts
Why this is correct
Comparing a host's DNS query volume and destination domains against its organizational peer group helps isolate anomalous behavior from standard operational traffic. If a single workstation exhibits a massive spike in query rate to an unusual external domain while its peers do not, this statistical outlier strongly suggests automated tunneling or beaconing activity. This comparative analysis filters out legitimate, high-volume services like content delivery networks that are common across the entire peer group.
- ✗
Check whether the user likes the website
Why it's wrong here
A user's subjective preference or affinity for a specific website provides no objective telemetry for identifying malicious network activity. DNS tunneling operates silently at the protocol level, often completely unbeknownst to the user, meaning subjective sentiment cannot confirm or deny the presence of an active covert channel. Security analysts must rely on technical indicators like packet captures and query logs rather than user sentiment.
- ✗
Count the number of icons on the desktop
Why it's wrong here
The number of shortcuts or icons present on a user's desktop environment is entirely unrelated to network-layer DNS telemetry. DNS tunneling is a network-based evasion technique that encapsulates non-DNS protocols within standard DNS queries, leaving no footprint on local desktop GUI configurations. Investigating superficial interface elements wastes critical triage time and fails to address the underlying packet-level anomalies.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.