CS0-003 Security Operations Practice Question
Which of the following log sources would be most useful for detecting DNS tunneling?
⚠ Common exam trap
The trap is that candidates pick firewall logs because DNS uses port 53, but firewalls log connections, not query contents — only DNS logs contain the query names and payloads needed to detect tunneling.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
DNS logs
DNS tunneling encodes data inside DNS queries and responses (often in subdomain labels or TXT records), so the authoritative DNS server logs and recursive resolver query logs are the only place where the full query strings are visible. Analyzing DNS logs for high-entropy subdomains, unusual query volume, or long TXT responses is the primary detection method. Firewall, auth, and EDR logs lack the DNS payload detail needed to spot the tunnel.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
DNS logs
Why this is correct
DNS logs record the specific domain queries (such as TXT, CNAME, or MX records) and responses that are manipulated during a DNS tunneling attack. Analyzing these logs allows security analysts to detect anomalies like unusually long subdomains, high query volume to a single authoritative name server, and encoded payloads within the queries.
- ✗
Firewall logs
Why it's wrong here
While firewall logs capture connection attempts, source/destination IP addresses, and port numbers (such as UDP port 53), they lack visibility into the application-layer payload of the DNS packets. Consequently, they cannot reveal the specific domain queries or encoded data payloads necessary to identify active tunneling behavior.
- ✗
Authentication logs
Why it's wrong here
Authentication logs track user login attempts, session establishments, privilege escalations, and credential usage across systems and active directory environments. They do not capture network layer or application layer protocol transactions, making them entirely blind to DNS query structures and tunneling activities.
- ✗
Endpoint EDR logs
Why it's wrong here
Endpoint Detection and Response (EDR) logs focus on host-level telemetry, such as process execution, registry modifications, and local file changes. Although EDR might flag a suspicious process initiating network connections, it typically does not perform the deep packet inspection or aggregate query analysis required to diagnose DNS tunneling.
Visual reference
Go deeper
Related to this question
Learn chapter
DNS Analysis and Anomaly Detection
Key term
Firewall
A firewall is a network security system that monitors and controls incoming and outgoing traffic based on predetermined security rules to protect trusted internal networks from untrusted external networks.
Key term
Detection
Detection is the process of identifying potential security incidents or anomalies by analyzing system data, logs, and network traffic.
About these practice questions
One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.