Courseiva

GCIH Practice Question: Detecting Evasive and Post-Exploitation Techniques

A threat hunter observes outbound DNS queries from an internal workstation to a domain that resolves to an IP address owned by a cloud provider. The queries contain long, random-looking subdomains such as 'a1b2c3d4e5f6g7h8.example.com'. The volume of queries is high and consistent, occurring every few seconds. Which post-exploitation technique is most likely in use?

⚠ Common exam trap

Test-takers frequently confuse DNS tunneling with domain fronting, which uses HTTPS SNI manipulation rather than DNS query encoding and would not produce long random subdomains.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

DNS tunneling for command-and-control or data exfiltration

DNS tunneling encodes data or C2 instructions in DNS queries, often using long, random-looking subdomains and high query volumes. The consistent timing and cloud-hosted destination are typical of a covert channel that abuses allowed DNS traffic to bypass egress filtering. Detecting such patterns requires analyzing DNS query length, entropy, and volume per host.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    DNS cache poisoning to redirect internal users

    Why it's wrong here

    DNS cache poisoning corrupts a resolver's cache to redirect legitimate domain lookups to malicious IPs. It does not generate high-volume queries with random subdomains from a single workstation. The observed behavior is outbound from one host to one domain, which is the opposite of poisoning a resolver to affect many users.

  • ✓

    DNS tunneling for command-and-control or data exfiltration

    Why this is correct

    High-volume DNS queries with long, random subdomains to a single domain are characteristic of DNS tunneling. Attackers encode data or commands in the subdomain fields to bypass network controls that allow DNS. The consistent timing and cloud-hosted destination further support a covert channel using DNS as the transport for C2 or exfiltration.

  • ✗

    Fast flux DNS to rotate C2 infrastructure

    Why it's wrong here

    Fast flux involves rapidly changing DNS A records for a domain to multiple compromised hosts, often with short TTLs. It does not produce long random subdomains or high-volume queries from a single host. The scenario describes a single domain with encoded subdomains, which is consistent with data encoding, not IP rotation.

  • ✗

    Domain fronting to hide C2 traffic behind a legitimate CDN

    Why it's wrong here

    Domain fronting uses a legitimate CDN domain in the TLS SNI while the HTTP Host header points to the attacker's domain, making traffic appear to go to a trusted service. It does not involve long random subdomains or high-volume DNS queries. The observed pattern is DNS-centric, not HTTPS-based, so domain fronting is not the technique in use.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

One of 322 original GCIH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.