Courseiva
OS and Network Forensics →hardMultiple Select

CHFI OS and Network Forensics Practice Question

A forensic analyst is examining a network packet capture for signs of data exfiltration. Which THREE of the following are common indicators of data exfiltration over DNS? (Select three.)

⚠ Common exam trap

The CHFI exam often tests the misconception that low TTL values are a definitive sign of exfiltration, but TTL manipulation is rarely used in DNS tunneling and is more commonly associated with legitimate DNS optimization or fast-flux networks.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

DNS responses with unusually large payloads (e.g., TXT records)

Option C is correct because DNS tunneling tools such as iodine and dnscat2 encode stolen data in TXT, NULL, or CNAME records, producing responses far larger than the typical 512-byte UDP DNS limit and thus a strong exfiltration indicator. Option D is correct because exfiltration over DNS requires many queries to carry data out, so a high volume of queries to a single domain (often thousands per hour) stands out against normal resolver traffic. Option E is correct because the encoded payload is placed in the leftmost label, generating long, random-looking subdomains such as 'aGVsbG8.evil.com' that are characteristic of DNS tunneling. Option A is not a reliable indicator: low TTLs are common in fast-flux and load-balancing setups and are not specific to exfiltration. Option B is also not specific, since clients legitimately query multiple configured or fallback DNS servers during normal resolution.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Low TTL values in DNS responses

    Why it's wrong here

    Low TTL values simply instruct recursive resolvers to cache the answer for a shorter period, which is often done for legitimate reasons such as fast failover or dynamic DNS updates. While a low TTL can help an attacker avoid cached responses and force repeated queries, it does not by itself indicate data exfiltration because it carries no payload or query-name entropy. Without supporting evidence like unusually large TXT responses or a high query rate for non-existent random-looking subdomains, low TTL is a weak, non-specific artifact.

  • ✗

    DNS queries sent to multiple different DNS servers

    Why it's wrong here

    A DNS tunnel is normally directed at a single authoritative server under the attacker's control, because the exfiltrated data must be reassembled from many query/response pairs; scattering queries across multiple different DNS servers would fragment the data and require an additional coordination mechanism. Legitimate endpoints, however, can query several resolvers due to DHCP-provided DNS entries, multiple network interfaces, or redundant DNS configurations. Thus, the use of multiple DNS servers is not inherently suspicious and does not align with the typical flow of DNS exfiltration.

  • ✓

    DNS responses with unusually large payloads (e.g., TXT records)

    Why this is correct

    In normal operation, DNS TXT records are used for verifiable text like SPF policies or domain ownership tokens and are rarely larger than a few hundred bytes; an attacker exfiltrating data will pad or encode payloads into TXT answers, causing response sizes to exceed typical benign traffic. Since a standard UDP DNS response without EDNS0 is limited to 512 bytes, responses that push against or exceed that limit (and require TCP fallback) are a solid anomaly. These oversized TXT responses, combined with a queried domain that also receives many random subdomain queries, are a hallmark of DNS tunneling.

  • ✓

    High volume of DNS queries to a single domain

    Why this is correct

    Because each DNS query name is constrained in length, a tunneling tool must issue a huge number of queries to move even modest amounts of data, causing a statistically significant volume spike for one destination domain. This is distinct from legitimate CDN or recursive traffic, which typically spreads across many domains or hostnames. High query volume to a single domain, especially one that is not a popular service and has no corresponding high web traffic, is a recognized indicator of DNS tunneling.

  • ✓

    DNS queries for random-looking subdomains

    Why this is correct

    Data exfiltration over DNS works by encoding binary data into the subdomain labels of a query, and the resulting labels often use high entropy character sets like base32 or hex, producing meaningless strings such as '3f9a2b7c' under a known domain. Benign subdomains are usually human-readable or follow a predictable pattern (e.g., 'www', 'mail', 'api'), so the presence of long random-looking subdomains with no dictionary meaning is a strong anomaly. The randomness can be quantified using entropy analysis, and a high Shannon entropy score for the left-most labels is a practical detection signal.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.