GCIH Network and Log Investigations Practice Question
A security analyst is reviewing a packet capture from a compromised host and observes a series of DNS queries for randomly generated subdomains of a single domain, each followed by a TXT record response containing encoded data. The queries occur at regular intervals of approximately 60 seconds. Which type of attack is most strongly indicated by this pattern?
⚠ Common exam trap
A common mix-up: candidates confuse DNS tunneling with other DNS-based attacks like cache poisoning or fast flux, which have different indicators such as forged responses or rapidly changing A records.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
DNS tunneling for command and control
DNS tunneling exploits the DNS protocol to carry data covertly. The random subdomains and TXT records with encoded payloads, combined with regular timing, strongly indicate a command-and-control channel. This method is popular because DNS is often allowed through firewalls. Recognizing this pattern allows incident handlers to block the domain and investigate the infected host for malware.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
DNS amplification DDoS
Why it's wrong here
DNS amplification attacks use open resolvers to send large responses to a spoofed victim IP, causing a denial of service. In this scenario, the queries originate from a single compromised host and receive TXT responses, not a flood of responses to a victim. The pattern is bidirectional and low-volume, inconsistent with amplification.
- ✗
Fast flux DNS
Why it's wrong here
Fast flux involves rapidly changing DNS A records to multiple compromised hosts to evade takedowns. The scenario describes TXT records with encoded data, not rapidly changing A records. While fast flux can be used in botnets, the specific indicators here—random subdomains and encoded TXT—are more characteristic of tunneling than flux.
- ✗
DNS cache poisoning
Why it's wrong here
DNS cache poisoning involves injecting false DNS records into a resolver's cache to redirect legitimate traffic to malicious IPs. The scenario shows regular queries with encoded TXT responses, not forged responses being injected into a cache. The periodic nature and data encoding point to a different technique, making cache poisoning an incorrect conclusion.
- ✓
DNS tunneling for command and control
Why this is correct
The use of randomly generated subdomains and TXT records with encoded data at regular intervals is a classic sign of DNS tunneling. Attackers encode command-and-control data or exfiltrated information within DNS queries and responses to bypass network controls. The consistent timing suggests automated beaconing, which is typical of such malware.
Visual reference
About these practice questions
One of 322 original GCIH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.