Courseiva

GCIH Network and Log Investigations Practice Question

An analyst is investigating potential data exfiltration via DNS tunneling. Which TWO of the following indicators would most strongly suggest this activity is occurring?

⚠ Common exam trap

Candidates often focus on the volume of DNS traffic alone, failing to distinguish between legitimate high-traffic DNS usage and the specific indicators of tunneling, such as atypical record types or encoded subdomain lengths.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A sudden increase in DNS TXT record requests

DNS tunneling uses DNS queries to encapsulate non-DNS traffic, bypassing standard firewalls. Detecting this requires looking for abnormal patterns in traffic volume and request frequency. By identifying unusually long subdomains or high volumes of TXT/NULL record types, analysts can pinpoint covert channels. This is critical for detecting C2 traffic that hides in plain sight within common, often permitted, network protocols.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    A sudden increase in DNS TXT record requests

    Why this is correct

    DNS TXT records are often used in tunneling because they can store arbitrary data strings. A significant spike in these requests, especially to an unknown or suspicious domain, is a strong indicator that an attacker is using the DNS protocol as a covert transport mechanism.

  • ✗

    High volumes of HTTP GET requests to internal IPs

    Why it's wrong here

    HTTP GET requests to internal IPs are typical of standard web application behavior and local network services. This traffic does not directly correlate with DNS tunneling, which specifically leverages the DNS protocol for communication rather than standard HTTP traffic over the web ports.

  • ✓

    Unusually long, randomized subdomain strings

    Why this is correct

    In DNS tunneling, the data being exfiltrated is encoded into the subdomain portion of the query. These subdomains often appear as long, high-entropy, randomized strings. Detecting these strings in logs is a hallmark technique for identifying data exfiltration hidden within legitimate DNS traffic.

  • ✗

    Frequent ICMP echo requests from the perimeter

    Why it's wrong here

    ICMP echo requests are related to the ping utility and network diagnostics. While ICMP can be used for covert channels, it is distinct from DNS tunneling. This indicator would point toward different exfiltration techniques rather than the specific misuse of the DNS protocol.

  • ✗

    TCP SYN floods targeting the local gateway

    Why it's wrong here

    A TCP SYN flood is a Denial of Service attack intended to overwhelm a target by exhausting connection resources. It has no functional relationship to DNS tunneling, which is an exfiltration or C2 communication method that relies on UDP-based DNS queries, not TCP connection states.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

This GCIH question is part of Courseiva's 322-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.