During a network traffic review, an analyst notices encrypted traffic to an unusual external IP address on TCP port 53. What is the most likely anomaly this indicates?
Attackers frequently use DNS tunneling to bypass firewalls by encapsulating non-DNS protocols and encrypted payloads inside DNS packets. Because TCP port 53 allows for larger, reliable data streams compared to UDP, persistent encrypted traffic on this port is a classic indicator of an active data exfiltration channel.