An incident responder reviews a packet capture from a compromised Windows workstation and notices periodic outbound DNS queries for random-looking subdomains such as 'a8f3c9e1.badguy.example'. Each query is followed by a TXT record response containing a short Base64 string. What technique is being used?
The random subdomains and TXT responses carrying Base64 data are characteristic of DNS tunneling, where an attacker encodes C2 instructions or exfiltrated data within DNS queries and responses. The use of TXT records to return payloads further confirms this, as legitimate DNS TXT records rarely contain such encoded data in this pattern.
Why this answer
The correct answer is DNS tunneling for command and control. Random subdomains combined with TXT records carrying Base64 data indicate that the attacker is using DNS as a covert channel to send commands or exfiltrate data. Legitimate DNS traffic rarely exhibits such encoded payloads, making this a strong indicator of compromise.
Exam trap
The trap here is assuming that any random-looking DNS query is DGA activity, when the presence of encoded TXT responses specifically points to DNS tunneling.