Courseiva

CHFI Mobile and Malware Forensics Practice Question

A security analyst is using Wireshark during a malware analysis session. The analyst observes a series of DNS queries to a domain 'malware-c2.example.com' every 60 seconds. This behavior is indicative of which malware characteristic?

⚠ Common exam trap

EC-Council often tests the distinction between DNS tunneling and C2 beaconing, where candidates mistakenly choose DNS tunneling because they see DNS queries, but the key differentiator is the regular, low-frequency pattern (beaconing) versus high-volume or encoded data in queries (tunneling).

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Command and control (C2) communication

The periodic DNS queries to 'malware-c2.example.com' every 60 seconds are a classic heartbeat or beaconing mechanism used by malware to maintain persistent communication with its command and control (C2) server. This regular check-in allows the attacker to send commands or receive stolen data without requiring the malware to initiate a direct connection, which could be blocked by firewalls. The fixed interval and specific domain indicate a programmed C2 channel rather than a one-time data transfer or tunneling technique.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Data exfiltration

    Why it's wrong here

    Data exfiltration involves the unauthorized transfer of data out of a network, commonly via HTTP POSTs or DNS lookup values that carry actual file contents or encoded sensitive information. In this capture, the observed queries are simple periodic DNS requests to a single domain, with no payload carrying data and no large response records being returned. Without evidence of data being embedded in the queries or responses, the activity does not meet the definition of data exfiltration.

  • ✗

    DNS tunneling

    Why it's wrong here

    DNS tunneling is an attack technique where the attacker encapsulates non-DNS data inside DNS query and response messages, often using long subdomains to encode data in Base64 or binary, and returning data in TXT records. The traffic seen here consists of short, periodic lookups to the same domain without variable subdomains, high query rates, or unusual record types like TXT, which would indicate tunneling. Thus, while the activity may be suspicious, it lacks the technical signature of DNS tunneling.

  • ✓

    Command and control (C2) communication

    Why this is correct

    This is characteristic of command and control (C2) communication, specifically beaconing, where compromised hosts send regular, low-volume queries to a domain controlled by the attacker to receive instructions or report status. The periodic nature, consistent destination, and absence of payload data are hallmarks of a C2 beacon, distinguishing it from data transfer or network scanning. DNS is a preferred C2 channel because it often bypasses firewalls and proxy filters.

  • ✗

    Propagation via network scanning

    Why it's wrong here

    Network propagation via scanning would manifest as a burst of connection attempts to many different IP addresses and ports, typically using TCP SYN packets to identify vulnerable services for lateral movement. In contrast, the observed activity is limited to DNS queries to a single domain, which does not enumerate hosts or services on the network. Therefore, the traffic pattern is inconsistent with malware attempting to spread by network scanning.

About these practice questions

One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.