CHFI OS and Network Forensics Practice Question
A network forensics analyst captures traffic from a suspected data exfiltration. In Wireshark, filtering for DNS queries containing a long subdomain with base64-encoded text suggests which technique?
⚠ Common exam trap
EC-Council often tests the distinction between data exfiltration techniques (tunneling) and network abuse attacks (amplification, poisoning, hijacking), so candidates mistakenly pick DNS amplification because it also involves unusual DNS traffic patterns.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
DNS tunneling
DNS tunneling encodes data (often base64) into DNS query subdomains to bypass network controls and exfiltrate information. Wireshark filtering for unusually long DNS queries with encoded text directly reveals this technique, as legitimate DNS queries rarely contain such payloads.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
DNS tunneling
Why this is correct
DNS tunneling is a covert channel in which an attacker embeds data payloads into DNS query labels and response records (commonly TXT) and exchanges that data with a domain the attacker controls. Unlike a simple resolution failure, these queries form a bidirectional communication stream that bypasses typical egress filters because UDP port 53 is almost always allowed to leave the network. In the captured traffic, this pattern appears as a high volume of unique subdomains or unusually large TXT responses, making it the correct diagnosis over the other choices.
- ✗
DNS hijacking
Why it's wrong here
DNS hijacking involves the unauthorized alteration of the DNS configuration or interception of DNS messages so that users' queries are redirected to a rogue resolver or poisoned address, often for phishing or credential theft. It does not create a hidden data stream over DNS; rather, it changes the destination of normal DNS resolution. Even if an attacker subsequently communicates with a victim, hijacking itself is a redirection mechanism, not an exfiltration channel, so it does not match the observed data transfer signature.
- ✗
DNS poisoning
Why it's wrong here
DNS poisoning, also known as cache poisoning, corrupts a recursive resolver's cache by injecting fraudulent DNS records — the classic Kaminsky attack is a prime example — thereby causing users to resolve legitimate domains to attacker-controlled IPs. The attack targets the integrity of resolution data, and the only 'payload' is the fake address, not exfiltrated information from the internal network. Nothing in the poisoned cache result carries a covert message back to a command-and-control server, so it is not a data exfiltration technique.
- ✗
DNS amplification
Why it's wrong here
DNS amplification is a DDoS technique whereby attackers send small DNS queries with a spoofed source IP to open resolvers, which then return large responses to the forged victim's address, saturating their bandwidth. The attacker does not need to receive or decode any data from the victim, and the victim connection is likely unrelated to the source of the anomaly. It is fundamentally a resource-exhaustion attack, not a covert bidirectional channel, so it cannot explain data being silently extracted from the network.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.