GCIH Practice Question: Detecting Evasive and Post-Exploitation Techniques
A threat hunter observes outbound DNS queries from an internal workstation to a domain that resolves to an IP address owned by a cloud provider. The queries contain long, random-looking subdomains such as 'a1b2c3d4e5f6g7h8.example.com'. The volume of queries is high and consistent, occurring every few seconds. Which post-exploitation technique is most likely in use?
⚠ Common exam trap
Test-takers frequently confuse DNS tunneling with domain fronting, which uses HTTPS SNI manipulation rather than DNS query encoding and would not produce long random subdomains.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
DNS tunneling for command-and-control or data exfiltration
DNS tunneling encodes data or C2 instructions in DNS queries, often using long, random-looking subdomains and high query volumes. The consistent timing and cloud-hosted destination are typical of a covert channel that abuses allowed DNS traffic to bypass egress filtering. Detecting such patterns requires analyzing DNS query length, entropy, and volume per host.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
DNS cache poisoning to redirect internal users
Why it's wrong here
DNS cache poisoning corrupts a resolver's cache to redirect legitimate domain lookups to malicious IPs. It does not generate high-volume queries with random subdomains from a single workstation. The observed behavior is outbound from one host to one domain, which is the opposite of poisoning a resolver to affect many users.
- ✓
DNS tunneling for command-and-control or data exfiltration
Why this is correct
High-volume DNS queries with long, random subdomains to a single domain are characteristic of DNS tunneling. Attackers encode data or commands in the subdomain fields to bypass network controls that allow DNS. The consistent timing and cloud-hosted destination further support a covert channel using DNS as the transport for C2 or exfiltration.
- ✗
Fast flux DNS to rotate C2 infrastructure
Why it's wrong here
Fast flux involves rapidly changing DNS A records for a domain to multiple compromised hosts, often with short TTLs. It does not produce long random subdomains or high-volume queries from a single host. The scenario describes a single domain with encoded subdomains, which is consistent with data encoding, not IP rotation.
- ✗
Domain fronting to hide C2 traffic behind a legitimate CDN
Why it's wrong here
Domain fronting uses a legitimate CDN domain in the TLS SNI while the HTTP Host header points to the attacker's domain, making traffic appear to go to a trusted service. It does not involve long random subdomains or high-volume DNS queries. The observed pattern is DNS-centric, not HTTPS-based, so domain fronting is not the technique in use.
Visual reference
About these practice questions
One of 322 original GCIH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.