Courseiva
Security Operations →easyMultiple Choice

CS0-003 Security Operations Practice Question

Which of the following is the best data source for detecting DNS tunneling activity?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

DNS logs

DNS logs contain the queries and responses; analyzing them for unusual domain patterns, large query volumes, or odd record types can reveal tunneling.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Firewall logs

    Why it's wrong here

    While firewall logs record connection attempts, port usage (such as UDP/TCP port 53), and packet counts, they typically lack the deep packet inspection capabilities required to analyze the actual DNS query and response payloads. Consequently, security analysts cannot inspect the specific subdomains or TXT records used in DNS tunneling attacks through standard firewall logs alone.

  • ✓

    DNS logs

    Why this is correct

    DNS logs capture the complete transaction details, including the requested domain names, query types (such as TXT, MX, or CNAME), and the corresponding server responses. This granular payload visibility is essential for identifying the high-frequency, anomalously long, or encoded subdomains characteristic of DNS tunneling and data exfiltration techniques.

  • ✗

    EDR telemetry

    Why it's wrong here

    Endpoint Detection and Response (EDR) telemetry excels at monitoring local host behaviors, process executions, registry changes, and file system modifications. However, it does not natively capture or parse the raw, network-wide DNS transaction payloads flowing between internal resolvers and external authoritative name servers, making it inefficient for direct network-level tunneling detection.

  • ✗

    NetFlow data

    Why it's wrong here

    NetFlow data provides valuable metadata regarding network conversations, including source/destination IP addresses, ports, protocols, and byte counts. While it can highlight volume anomalies on port 53, it does not capture the actual application-layer DNS payload, rendering it unable to distinguish legitimate queries from malicious, encapsulated data payloads.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.