Courseiva
Security Operations →easyMultiple Choice

CS0-003 Security Operations Practice Question

Which of the following log sources would be most useful for detecting DNS tunneling?

⚠ Common exam trap

The trap is that candidates pick firewall logs because DNS uses port 53, but firewalls log connections, not query contents — only DNS logs contain the query names and payloads needed to detect tunneling.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

DNS logs

DNS tunneling encodes data inside DNS queries and responses (often in subdomain labels or TXT records), so the authoritative DNS server logs and recursive resolver query logs are the only place where the full query strings are visible. Analyzing DNS logs for high-entropy subdomains, unusual query volume, or long TXT responses is the primary detection method. Firewall, auth, and EDR logs lack the DNS payload detail needed to spot the tunnel.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    DNS logs

    Why this is correct

    DNS logs record the specific domain queries (such as TXT, CNAME, or MX records) and responses that are manipulated during a DNS tunneling attack. Analyzing these logs allows security analysts to detect anomalies like unusually long subdomains, high query volume to a single authoritative name server, and encoded payloads within the queries.

  • ✗

    Firewall logs

    Why it's wrong here

    While firewall logs capture connection attempts, source/destination IP addresses, and port numbers (such as UDP port 53), they lack visibility into the application-layer payload of the DNS packets. Consequently, they cannot reveal the specific domain queries or encoded data payloads necessary to identify active tunneling behavior.

  • ✗

    Authentication logs

    Why it's wrong here

    Authentication logs track user login attempts, session establishments, privilege escalations, and credential usage across systems and active directory environments. They do not capture network layer or application layer protocol transactions, making them entirely blind to DNS query structures and tunneling activities.

  • ✗

    Endpoint EDR logs

    Why it's wrong here

    Endpoint Detection and Response (EDR) logs focus on host-level telemetry, such as process execution, registry modifications, and local file changes. Although EDR might flag a suspicious process initiating network connections, it typically does not perform the deep packet inspection or aggregate query analysis required to diagnose DNS tunneling.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.