Courseiva

GCIH Practice Question: Detecting Exploitation and Covert Communication Tools

An incident responder reviews a packet capture from a compromised Windows workstation and notices periodic outbound DNS queries for random-looking subdomains such as 'a8f3c9e1.badguy.example'. Each query is followed by a TXT record response containing a short Base64 string. What technique is being used?

⚠ Common exam trap

The trap here is assuming that any random-looking DNS query is DGA activity, when the presence of encoded TXT responses specifically points to DNS tunneling.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

DNS tunneling for command and control

The correct answer is DNS tunneling for command and control. Random subdomains combined with TXT records carrying Base64 data indicate that the attacker is using DNS as a covert channel to send commands or exfiltrate data. Legitimate DNS traffic rarely exhibits such encoded payloads, making this a strong indicator of compromise.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Fast flux DNS

    Why it's wrong here

    Fast flux DNS rapidly changes the IP addresses associated with a domain to evade takedowns, but it does not involve encoding data in TXT records. The observed pattern of Base64 in TXT responses points to data transfer over DNS, not to a resilient hosting technique like fast flux.

  • ✓

    DNS tunneling for command and control

    Why this is correct

    The random subdomains and TXT responses carrying Base64 data are characteristic of DNS tunneling, where an attacker encodes C2 instructions or exfiltrated data within DNS queries and responses. The use of TXT records to return payloads further confirms this, as legitimate DNS TXT records rarely contain such encoded data in this pattern.

  • ✗

    DNS cache poisoning

    Why it's wrong here

    DNS cache poisoning involves injecting false DNS records into a resolver's cache to redirect traffic, not using DNS queries to exfiltrate or receive commands. The scenario shows a client repeatedly querying attacker-controlled domains and receiving encoded data, which is an active covert channel, not a cache manipulation attack.

  • ✗

    Domain generation algorithm (DGA) beaconing

    Why it's wrong here

    While DGA-generated domains also appear random, they are used to locate C2 servers, not to carry data in TXT responses. Here the TXT record contains Base64 payload, indicating data transfer over DNS rather than simple domain resolution. DGA would typically show NXDOMAIN responses or successful A record lookups, not TXT-based data exchange.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

Courseiva writes every GCIH question from scratch — 322 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.