GCIH Practice Question: Detecting Exploitation and Covert Communication Tools
An incident responder reviews a packet capture from a compromised Windows workstation and notices periodic outbound DNS queries for random-looking subdomains such as 'a8f3c9e1.badguy.example'. Each query is followed by a TXT record response containing a short Base64 string. What technique is being used?
⚠ Common exam trap
The trap here is assuming that any random-looking DNS query is DGA activity, when the presence of encoded TXT responses specifically points to DNS tunneling.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
DNS tunneling for command and control
The correct answer is DNS tunneling for command and control. Random subdomains combined with TXT records carrying Base64 data indicate that the attacker is using DNS as a covert channel to send commands or exfiltrate data. Legitimate DNS traffic rarely exhibits such encoded payloads, making this a strong indicator of compromise.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Fast flux DNS
Why it's wrong here
Fast flux DNS rapidly changes the IP addresses associated with a domain to evade takedowns, but it does not involve encoding data in TXT records. The observed pattern of Base64 in TXT responses points to data transfer over DNS, not to a resilient hosting technique like fast flux.
- ✓
DNS tunneling for command and control
Why this is correct
The random subdomains and TXT responses carrying Base64 data are characteristic of DNS tunneling, where an attacker encodes C2 instructions or exfiltrated data within DNS queries and responses. The use of TXT records to return payloads further confirms this, as legitimate DNS TXT records rarely contain such encoded data in this pattern.
- ✗
DNS cache poisoning
Why it's wrong here
DNS cache poisoning involves injecting false DNS records into a resolver's cache to redirect traffic, not using DNS queries to exfiltrate or receive commands. The scenario shows a client repeatedly querying attacker-controlled domains and receiving encoded data, which is an active covert channel, not a cache manipulation attack.
- ✗
Domain generation algorithm (DGA) beaconing
Why it's wrong here
While DGA-generated domains also appear random, they are used to locate C2 servers, not to carry data in TXT responses. Here the TXT record contains Base64 payload, indicating data transfer over DNS rather than simple domain resolution. DGA would typically show NXDOMAIN responses or successful A record lookups, not TXT-based data exchange.
Visual reference
About these practice questions
Courseiva writes every GCIH question from scratch — 322 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.