CS0-003 Security Operations Practice Question
Which of the following is the best data source for detecting DNS tunneling activity?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
DNS logs
DNS logs contain the queries and responses; analyzing them for unusual domain patterns, large query volumes, or odd record types can reveal tunneling.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Firewall logs
Why it's wrong here
While firewall logs record connection attempts, port usage (such as UDP/TCP port 53), and packet counts, they typically lack the deep packet inspection capabilities required to analyze the actual DNS query and response payloads. Consequently, security analysts cannot inspect the specific subdomains or TXT records used in DNS tunneling attacks through standard firewall logs alone.
- ✓
DNS logs
Why this is correct
DNS logs capture the complete transaction details, including the requested domain names, query types (such as TXT, MX, or CNAME), and the corresponding server responses. This granular payload visibility is essential for identifying the high-frequency, anomalously long, or encoded subdomains characteristic of DNS tunneling and data exfiltration techniques.
- ✗
EDR telemetry
Why it's wrong here
Endpoint Detection and Response (EDR) telemetry excels at monitoring local host behaviors, process executions, registry changes, and file system modifications. However, it does not natively capture or parse the raw, network-wide DNS transaction payloads flowing between internal resolvers and external authoritative name servers, making it inefficient for direct network-level tunneling detection.
- ✗
NetFlow data
Why it's wrong here
NetFlow data provides valuable metadata regarding network conversations, including source/destination IP addresses, ports, protocols, and byte counts. While it can highlight volume anomalies on port 53, it does not capture the actual application-layer DNS payload, rendering it unable to distinguish legitimate queries from malicious, encapsulated data payloads.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.