GCIH Network and Log Investigations Practice Question
An analyst is investigating potential data exfiltration via DNS tunneling. Which TWO of the following indicators would most strongly suggest this activity is occurring?
⚠ Common exam trap
Candidates often focus on the volume of DNS traffic alone, failing to distinguish between legitimate high-traffic DNS usage and the specific indicators of tunneling, such as atypical record types or encoded subdomain lengths.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A sudden increase in DNS TXT record requests
DNS tunneling uses DNS queries to encapsulate non-DNS traffic, bypassing standard firewalls. Detecting this requires looking for abnormal patterns in traffic volume and request frequency. By identifying unusually long subdomains or high volumes of TXT/NULL record types, analysts can pinpoint covert channels. This is critical for detecting C2 traffic that hides in plain sight within common, often permitted, network protocols.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
A sudden increase in DNS TXT record requests
Why this is correct
DNS TXT records are often used in tunneling because they can store arbitrary data strings. A significant spike in these requests, especially to an unknown or suspicious domain, is a strong indicator that an attacker is using the DNS protocol as a covert transport mechanism.
- ✗
High volumes of HTTP GET requests to internal IPs
Why it's wrong here
HTTP GET requests to internal IPs are typical of standard web application behavior and local network services. This traffic does not directly correlate with DNS tunneling, which specifically leverages the DNS protocol for communication rather than standard HTTP traffic over the web ports.
- ✓
Unusually long, randomized subdomain strings
Why this is correct
In DNS tunneling, the data being exfiltrated is encoded into the subdomain portion of the query. These subdomains often appear as long, high-entropy, randomized strings. Detecting these strings in logs is a hallmark technique for identifying data exfiltration hidden within legitimate DNS traffic.
- ✗
Frequent ICMP echo requests from the perimeter
Why it's wrong here
ICMP echo requests are related to the ping utility and network diagnostics. While ICMP can be used for covert channels, it is distinct from DNS tunneling. This indicator would point toward different exfiltration techniques rather than the specific misuse of the DNS protocol.
- ✗
TCP SYN floods targeting the local gateway
Why it's wrong here
A TCP SYN flood is a Denial of Service attack intended to overwhelm a target by exhausting connection resources. It has no functional relationship to DNS tunneling, which is an exfiltration or C2 communication method that relies on UDP-based DNS queries, not TCP connection states.
Visual reference
About these practice questions
This GCIH question is part of Courseiva's 322-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.