CEH Practice Question: Malware, Social Engineering and Network Attacks
An organization's security team observes a surge in outgoing DNS queries to external servers from a single internal host, with each query returning unusually large responses (e.g., 4000 bytes). The host is not configured as a DNS resolver. Which attack is MOST likely occurring?
⚠ Common exam trap
The CEH exam often tests the distinction between DNS tunneling and DNS amplification. Candidates might mistakenly choose DNS amplification DDoS attack (C) by focusing solely on 'large responses' and misinterpreting the internal host as the *victim* of an amplification attack. However, the critical detail is that the internal host is *sending* the outgoing queries and *receiving* the large responses, which is characteristic of DNS tunneling (D) where data is exfiltrated or commanded. In a DNS amplification attack, the victim *receives* large responses without initiating the queries themselves (their IP is spoofed).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
DNS tunneling
The scenario describes a single internal host initiating a surge of outgoing DNS queries to external servers and receiving unusually large responses (e.g., 4000 bytes). This behavior, particularly from a host not configured as a DNS resolver, is a strong indicator of DNS tunneling. In DNS tunneling, a compromised host establishes a covert communication channel by encapsulating data within DNS queries and responses, often for data exfiltration or command and control. Large DNS responses, frequently utilizing record types like TXT, are commonly employed to transfer significant amounts of data back to the compromised host. DNS amplification DDoS attacks, in contrast, involve an attacker spoofing a victim's IP address to send small queries to open resolvers, causing the victim to be overwhelmed by large, unsolicited responses; the victim does not actively send the initial queries in this scenario.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
DNS cache poisoning
Why it's wrong here
DNS cache poisoning involves injecting forged or malicious data into a DNS resolver's cache, causing it to return incorrect IP addresses for legitimate domains. While this redirects user traffic to attacker-controlled servers, it does not inherently generate a large volume of outgoing DNS responses from the poisoned server itself. The attack manipulates resolution, rather than creating a surge in response traffic.
- ✗
DNS zone transfer
Why it's wrong here
A DNS zone transfer is a legitimate process where a secondary DNS server requests and receives a full copy of a zone file from a primary DNS server. This mechanism ensures data consistency and redundancy across authoritative DNS servers. Although it involves data transfer, it is a controlled, authorized replication process, not an unsolicited attack that would cause an unexpected, massive surge in outgoing responses from a server.
- ✗
DNS amplification DDoS attack
Why it's wrong here
A DNS amplification DDoS attack leverages open recursive DNS resolvers to flood a target with an overwhelming volume of DNS response traffic. Attackers send small DNS queries with a spoofed source IP address (the target's IP) to numerous vulnerable resolvers, which then send much larger responses to the unsuspecting victim. This technique effectively uses the compromised or misconfigured DNS servers as amplifiers, generating a significant surge in outgoing data towards the target.
- ✓
DNS tunneling
Why this is correct
DNS tunneling is a technique used to encapsulate data of other protocols within DNS queries and responses, often for covert communication or data exfiltration. While it involves using DNS traffic to bypass firewalls or security controls, its primary goal is to establish a hidden communication channel, not to generate an enormous volume of large, legitimate-looking DNS responses for denial-of-service. The data volume is typically limited by the tunneling payload, not designed for massive amplification.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 913 original CEH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.