CS0-003 Security Operations Practice Question
During a network traffic review, an analyst notices encrypted traffic to an unusual external IP address on TCP port 53. What is the most likely anomaly this indicates?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Data exfiltration via DNS tunnelling
Port 53 is used for DNS, which typically uses UDP. Encrypted traffic on TCP/53 suggests DNS tunnelling, where data is exfiltrated inside DNS queries and responses.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Normal DNS resolution
Why it's wrong here
Standard DNS resolution primarily utilizes UDP port 53 for lightweight queries, occasionally falling back to TCP port 53 only for large zone transfers or responses exceeding 512 bytes. It does not natively encrypt this traffic. Finding persistent, encrypted traffic on TCP port 53 indicates highly anomalous behavior rather than standard, unencrypted name resolution.
- ✗
Beaconing to command and control
Why it's wrong here
While command-and-control (C2) agents do beacon to external servers, this activity typically relies on standard web protocols like HTTP or HTTPS over ports 80 and 443 to blend in with normal user browsing. While DNS can be used for C2, the specific presence of heavy, encrypted TCP/53 traffic is more indicative of bulk data exfiltration via tunneling rather than low-and-slow beaconing pulses.
- ✓
Data exfiltration via DNS tunnelling
Why this is correct
Attackers frequently use DNS tunneling to bypass firewalls by encapsulating non-DNS protocols and encrypted payloads inside DNS packets. Because TCP port 53 allows for larger, reliable data streams compared to UDP, persistent encrypted traffic on this port is a classic indicator of an active data exfiltration channel.
- ✗
HTTP smuggling attack
Why it's wrong here
HTTP request smuggling is an exploitation technique that targets the discrepancies in how front-end proxies and back-end servers parse HTTP request boundaries. This attack vector is strictly confined to HTTP/HTTPS traffic (typically ports 80 and 443) and has no technical relationship with DNS protocols or TCP port 53.
Go deeper
Related to this question
About these practice questions
This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.