hardMultiple Choice
CS0-003 Practice Question: During a threat hunting exercise, an analyst…
During a threat hunting exercise, an analyst formulates a hypothesis that an attacker may be using DNS tunneling to exfiltrate data. Which data source would provide the best evidence to confirm or deny this hypothesis?
⚠ Common exam trap
The CS0-004 exam often tests the misconception that NetFlow or firewall logs are sufficient for detecting data exfiltration, when in reality only deep packet inspection can reveal the payload content necessary to confirm DNS tunneling.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Deep packet inspection (DPI) of DNS traffic
Deep packet inspection (DPI) of DNS traffic is the best evidence because DNS tunneling works by encoding data within DNS queries and responses, often using non-standard record types (e.g., TXT, NULL) or unusually long domain names. DPI can decode the payload within DNS packets to reveal hidden data, whereas other methods only see metadata or connection summaries. This allows the analyst to directly inspect the content of DNS messages for signs of exfiltration, such as base64-encoded data or anomalous query patterns.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Firewall logs showing allowed outbound connections
Why it's wrong here
Firewall logs primarily record connection metadata such as source/destination IP addresses, ports, protocols, and the action taken (allow/deny). These logs operate at lower layers of the OSI model and typically do not perform deep packet inspection to analyze the application-layer payload of traffic. Consequently, they cannot reveal the specific content of DNS queries or responses, making them ineffective for detecting data encoded within DNS traffic for tunneling.
- ✗
NetFlow records from the border router
Why it's wrong here
NetFlow records provide summaries of network traffic flows, detailing metadata like source and destination IP addresses, ports, protocols, and byte/packet counts for a given conversation. Crucially, NetFlow explicitly does not capture the actual data payload of the packets themselves. Without the ability to inspect the content within DNS queries or responses, NetFlow cannot identify the embedded data characteristic of DNS tunneling.
- ✗
EndPoint detection and response (EDR) logs showing DNS client activity
Why it's wrong here
Endpoint Detection and Response (EDR) logs provide granular visibility into activities occurring on an endpoint, including process execution and network connections initiated by those processes. While EDR can show which process made a DNS query and the destination DNS server, it typically does not capture the full, raw content of the DNS query or response payload. This limitation prevents the detection of data exfiltration or command-and-control communication hidden within the specific fields of DNS packets.
- ✓
Deep packet inspection (DPI) of DNS traffic
Why this is correct
Deep Packet Inspection (DPI) involves a thorough examination of the entire network packet, including its application-layer payload, not just the header information. When applied to DNS traffic, DPI can analyze the full content of DNS queries and responses, such as unusually long domain names, non-standard record types, or encoded data within these fields. This capability is essential for identifying the subtle anomalies and data patterns indicative of DNS tunneling, where data is covertly embedded.
Visual reference
Go deeper
Related to this question
Learn chapter
Threat Hunting Techniques and Hypothesis Development
Key term
Threat hunting
Threat hunting is a proactive cybersecurity practice where analysts actively search networks, endpoints, and logs for hidden threats that have evaded automated security tools.
Key term
Metadata
Metadata is data that describes other data, providing context such as when a file was created, who created it, or its size.
About these practice questions
Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.