Courseiva

CCNA Network and Log Investigations Questions

21 questions · Network and Log Investigations · All types, answers revealed

1
MCQhard

You are investigating an alert regarding a 'Beaconing' pattern. Which aspect of the network connection is most indicative of automated C2 communication versus human browsing activity?

A.The total volume of data transferred.
B.The consistency of the time interval between connections.
C.The destination port used for the traffic.
D.The protocol used by the connection.
AnswerB

Automated C2 beacons are programmed to check in at specific intervals, often with added 'jitter' to evade detection. The consistency of these timing patterns across long durations is a primary indicator of automated, non-human network activity, distinguishing it from the erratic nature of human web browsing.

Why this answer

Beaconing refers to periodic, consistent communication patterns between a compromised host and a C2 server. While human browsing is stochastic and unpredictable, automated beacons often exhibit high regularity in interval and small, consistent packet sizes. Identifying these 'heartbeat' patterns in network traffic analysis is critical for detecting persistent threats that avoid large, noticeable data bursts but maintain constant connectivity for command receipt.

Exam trap

Candidates often focus on the volume of data transferred. They incorrectly assume that high-volume data exfiltration is the primary indicator of C2, overlooking the regularity of small, heartbeat-like automated beacons.

2
MCQhard

A security analyst is reviewing a packet capture from a compromised host and observes a series of DNS queries for randomly generated subdomains of a single domain, each followed by a TXT record response containing encoded data. The queries occur at regular intervals of approximately 60 seconds. Which type of attack is most strongly indicated by this pattern?

A.DNS amplification DDoS
B.Fast flux DNS
C.DNS cache poisoning
D.DNS tunneling for command and control
AnswerD

The use of randomly generated subdomains and TXT records with encoded data at regular intervals is a classic sign of DNS tunneling. Attackers encode command-and-control data or exfiltrated information within DNS queries and responses to bypass network controls. The consistent timing suggests automated beaconing, which is typical of such malware.

Why this answer

DNS tunneling exploits the DNS protocol to carry data covertly. The random subdomains and TXT records with encoded payloads, combined with regular timing, strongly indicate a command-and-control channel. This method is popular because DNS is often allowed through firewalls.

Recognizing this pattern allows incident handlers to block the domain and investigate the infected host for malware.

Exam trap

The trap here is confusing DNS tunneling with other DNS-based attacks like cache poisoning or fast flux, which have different indicators such as forged responses or rapidly changing A records.

3
MCQmedium

An incident responder notices an unusual outbound connection from a workstation to an external IP address on TCP port 443. Packet capture analysis shows that the SSL/TLS handshake completes, but the subsequent application-layer data payload is fully encrypted and does not match standard HTTPS browser traffic patterns. Which log investigation method provides the most reliable approach to determine if this traffic represents malicious command and control activity?

A.Perform a reverse DNS lookup on the destination IP address to verify if the domain belongs to a known content delivery network.
B.Inspect the certificate issuer authority within the TLS handshake to confirm if it matches internal corporate enterprise signing policies.
C.Correlate the network connection timestamp with endpoint process execution logs to identify the exact binary that initiated the socket.
D.Analyze the TCP window size scaling factors during the initial three-way handshake to detect anomalies indicative of tunneling tools.
AnswerC

Correlating network connection timestamps with endpoint process execution logs allows analysts to identify the exact binary that initiated the socket. This bridges the visibility gap between network telemetry and host activity, confirming whether an unauthorized script or tool spawned the connection.

Why this answer

Correlating endpoint process execution logs with network connection data via Sysmon Event ID 3 and Event ID 1 reveals the parent process responsible for establishing the socket. Relying solely on destination port 443 or external reputation feeds is insufficient because modern adversaries frequently tunnel malicious traffic over standard ports and encrypted channels to blend in with legitimate enterprise web traffic.

Exam trap

Candidates often assume that standard TLS traffic on port 443 is inherently safe or focus heavily on external IP reputation checks, missing the fact that attackers routinely leverage standard ports for encrypted command and control channels.

4
Multi-Selectmedium

An analyst is investigating potential data exfiltration via DNS tunneling. Which TWO of the following indicators would most strongly suggest this activity is occurring?

Select 2 answers
A.A sudden increase in DNS TXT record requests
B.High volumes of HTTP GET requests to internal IPs
C.Unusually long, randomized subdomain strings
D.Frequent ICMP echo requests from the perimeter
E.TCP SYN floods targeting the local gateway
AnswersA, C

DNS TXT records are often used in tunneling because they can store arbitrary data strings. A significant spike in these requests, especially to an unknown or suspicious domain, is a strong indicator that an attacker is using the DNS protocol as a covert transport mechanism.

Why this answer

DNS tunneling uses DNS queries to encapsulate non-DNS traffic, bypassing standard firewalls. Detecting this requires looking for abnormal patterns in traffic volume and request frequency. By identifying unusually long subdomains or high volumes of TXT/NULL record types, analysts can pinpoint covert channels.

This is critical for detecting C2 traffic that hides in plain sight within common, often permitted, network protocols.

Exam trap

Candidates often focus on the volume of DNS traffic alone, failing to distinguish between legitimate high-traffic DNS usage and the specific indicators of tunneling, such as atypical record types or encoded subdomain lengths.

5
Multi-Selectmedium

An incident handler is analyzing a packet capture to identify command-and-control (C2) communication. Which two characteristics are most indicative of C2 traffic? (Choose two.)

Select 2 answers
A.Use of HTTP GET requests with long, random-looking URI parameters
B.Large outbound data transfers to an external IP address during non-business hours
C.Periodic connections to the same external IP address at regular intervals
D.Connections to an external IP address on a non-standard port that is not associated with any known service
E.Repeated DNS queries for a domain with a high entropy subdomain
AnswersC, E

Periodic connections at regular intervals, often called beaconing, are a hallmark of C2 communication because malware typically checks in with its controller at set times to receive commands or exfiltrate data. This pattern is distinct from normal user traffic, which is more random. The regularity can be configured by the attacker to blend in, but it remains a strong indicator.

Why this answer

Beaconing and DNS tunneling are two strong indicators of C2 communication. Beaconing involves regular, periodic connections that malware uses to check in with its controller. DNS tunneling encodes data in DNS queries, often using high entropy subdomains to carry commands or exfiltrate data.

Other characteristics like non-standard ports or large transfers may be present but are not as specific to C2, as they can occur in legitimate traffic. Combining multiple indicators increases confidence.

Exam trap

The trap here is focusing on port numbers or data volume alone, but C2 can use standard ports like 80 or 443, and exfiltration may be separate; the key is the regularity and encoding patterns.

6
Multi-Selectmedium

An incident responder is analyzing a network capture to identify potential command-and-control (C2) communication. The capture shows a workstation making regular DNS queries to 'update.microsoft.com' every 60 seconds, each followed by a small HTTPS session to a different IP address. The HTTPS sessions use self-signed certificates and the User-Agent string is 'Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)'. Which TWO of the following indicators most strongly suggest malicious C2 activity? (Choose two.)

Select 2 answers
A.The DNS queries are for a legitimate domain but resolve to multiple IP addresses.
B.The DNS queries occur at regular 60-second intervals.
C.The HTTPS sessions are to different IP addresses each time.
D.The User-Agent string is outdated and inconsistent with the operating system.
E.The HTTPS sessions use self-signed certificates.
AnswersD, E

An outdated User-Agent like 'MSIE 6.0' on a modern system is a red flag. Malware authors often hardcode old User-Agent strings, while legitimate applications use current ones. Inconsistency with the OS further suggests spoofing. This is a common indicator of C2 traffic, as it deviates from normal user behavior.

Why this answer

The correct answers are that the HTTPS sessions use self-signed certificates and the User-Agent string is outdated and inconsistent. Self-signed certificates are a hallmark of malware C2 because they are not trusted and often used to avoid detection. An outdated User-Agent like MSIE 6.0 on a modern system suggests the traffic is generated by malware with hardcoded strings.

Together, these strongly indicate malicious C2 activity, whereas the other options can be benign.

Exam trap

The trap here is focusing on the regular intervals or multiple IPs, which can be legitimate, while ignoring the more definitive indicators like self-signed certificates and outdated User-Agent.

7
MCQmedium

An incident handler is examining a packet capture from a compromised workstation and observes a series of DNS queries for domains like 'a1b2c3d4e5.exfil.example.com', each followed by a large TXT response. The queries are sent at regular 30-second intervals, and the subdomains contain random-looking alphanumeric strings. Which of the following techniques is MOST likely being used by the attacker?

A.DNS cache poisoning to redirect traffic
B.DNS tunneling for data exfiltration
C.Fast-flux DNS for resilience
D.Domain generation algorithm (DGA) for C2
AnswerB

The regular intervals, random subdomains, and large TXT responses are classic signs of DNS tunneling. Attackers encode stolen data in DNS queries or responses to bypass firewalls that allow DNS. The consistent timing and high volume of TXT records indicate automated exfiltration, not normal DNS behavior. This scenario matches the pattern of tools like iodine or dnscat2.

Why this answer

The correct answer is DNS tunneling for data exfiltration. The combination of regular intervals, random subdomains, and large TXT responses is a hallmark of DNS tunneling, where attackers encode data in DNS queries and responses to bypass network filters. This allows stealthy exfiltration even when other protocols are blocked.

Fast-flux, cache poisoning, and DGA do not involve such data transfer patterns.

Exam trap

The trap here is confusing DNS tunneling with DGA, but DGA typically results in failed queries, while tunneling involves successful data exchange.

8
MCQmedium

You are analyzing a PCAP and notice a large number of packets with the 'RST' flag set. What is the most likely cause for this behavior in an incident context?

A.Successful data transfer.
B.Port scanning activity.
C.Normal encrypted session renegotiation.
D.DNS zone transfer.
AnswerB

Port scanners often trigger RST responses when they attempt to connect to closed ports. When a scanner sends a SYN packet to a closed port, the target host responds with an RST/ACK to signal the connection is refused, creating a noticeable pattern of RST packets in traffic.

Why this answer

The TCP RST (Reset) flag is used to abruptly terminate a connection. A surge of these packets can indicate an active port scan, a misconfigured firewall rejecting unauthorized traffic, or an attacker attempting to clear out half-open connections. Understanding TCP state transitions is fundamental to identifying network scanning or denial-of-service attempts during the investigation of anomalous traffic patterns in packet captures.

Exam trap

Candidates frequently assume a flood of RST packets indicates a DoS attack, missing the common diagnostic pattern where port scanners trigger RST responses from closed ports.

9
MCQmedium

An incident handler is investigating a suspected data exfiltration on a Windows workstation. The SIEM generated an alert for a large outbound transfer to an unfamiliar IP address. The handler needs to determine which process initiated the connection. Which built-in Windows tool is most appropriate to correlate the active network connection to its owning process?

A.netstat -ano
B.nslookup
C.tracert
D.arp -a
AnswerA

The -ano flags list all connections with their owning process ID (PID) in numeric form. Combined with Task Manager or tasklist, the PID maps directly to the executable, allowing the handler to identify which process initiated the suspicious outbound transfer. This is the fastest native method to correlate a live connection to its process without additional tooling.

Why this answer

Correlating a live network connection to its owning process is a core incident response task. The netstat -ano command provides the essential PID mapping, which can then be resolved to an executable using tasklist or Task Manager. This native capability allows rapid triage without installing additional tools, directly answering which process initiated the suspicious outbound transfer.

Exam trap

The trap here is assuming that DNS or route tracing tools can attribute network activity to a process, when only connection listing tools with PID output can do that.

10
MCQhard

During an investigation of a suspected lateral movement attempt within an Active Directory environment, an incident handler needs to isolate authentication events involving Kerberos ticket-granting service (TGS) requests that indicate potential Kerberoasting activity. Which Windows Security Event Log ID should the analyst examine to identify abnormal requests for service principal names (SPNs) using weak encryption algorithms?

A.Security Event ID 4624
B.Security Event ID 4768
C.Security Event ID 4771
D.Security Event ID 4769
AnswerD

Event ID 4769 is logged for Kerberos service ticket (TGS) requests, recording the account, requested SPN and encryption type. Filtering for weak RC4 encryption and abnormal SPN requests exposes Kerberoasting, where attackers request service tickets to crack service account passwords offline.

Why this answer

Windows Security Event Log ID 4769 is generated whenever a Kerberos service ticket is requested. By filtering for Event ID 4769 and analyzing the encryption type field, analysts can spot requests using older, weaker encryption standards like RC4, which are heavily utilized during offline Kerberoasting password cracking attacks against service accounts.

Exam trap

Many analysts confuse Event ID 4768, which tracks Ticket Granting Ticket (TGT) requests during initial authentication, with Event ID 4769, which tracks Service Ticket (TGS) requests used specifically for Kerberoasting.

11
MCQmedium

An analyst discovers a suspicious file named 'svchost.exe' running from a user's 'AppData' directory. Why is this highly suspicious?

A.It is always a virus.
B.Svchost must always run as SYSTEM.
C.Legitimate svchost.exe resides in System32.
D.Svchost cannot be executed by users.
AnswerC

The actual Windows svchost.exe binary is located in C:\Windows\System32. When an executable with the same name is found in a user's AppData directory, it is almost certainly a malicious attempt to hide in plain sight while maintaining persistence, which is a classic indicator of compromise.

Why this answer

The legitimate svchost.exe process is a core Windows system component that resides in the System32 directory and is launched by the Service Control Manager. It is designed to host multiple Windows services. Attackers often rename their malicious binaries to 'svchost.exe' to blend in with legitimate processes, but they rarely place them in user-writable directories like AppData.

Detecting this is a key indicator of malware masquerading as system processes.

Exam trap

Candidates assume svchost.exe running from any folder is legitimate because it is a known Windows binary, ignoring the importance of execution path context.

12
MCQeasy

An incident handler is investigating a suspected compromised Windows workstation. They review Windows Security event logs and notice a large number of Event ID 4625 (An account failed to log on) followed by a single Event ID 4624 (An account was successfully logged on) from the same source IP within a short period. Which of the following best describes the activity?

A.A user mistyped their password several times before logging in successfully.
B.A successful brute-force attack against a user account.
C.A password-spraying attack targeting multiple accounts.
D.An account lockout policy being triggered and then reset.
AnswerB

Multiple failed logon attempts (4625) followed by a success (4624) from the same source IP is the classic pattern of a brute-force attack. The attacker tried many passwords until one worked. This is a common technique for gaining initial access. The short timeframe indicates automated tools. Therefore, this best describes the activity.

Why this answer

The correct answer is a successful brute-force attack. The pattern of many failed logon attempts (Event ID 4625) followed by a successful logon (Event ID 4624) from the same source IP in a short period is indicative of a brute-force attack. The attacker systematically tried passwords until one worked.

This is a common initial access technique, and incident handlers should investigate the source IP and check for further compromise.

Exam trap

The trap here is assuming it's a password-spraying attack, but spraying targets multiple accounts with few attempts each, while this scenario shows many failures for likely one account.

13
MCQmedium

An incident responder notices a spike in outbound traffic on port 443 originating from a server that normally only communicates with a local database. Which tool is most effective for identifying the specific process responsible for this anomalous network activity?

A.tcpdump -i eth0
B.netstat -ano
C.nmap -sV target
D.ifconfig -a
AnswerB

The -ano flags in netstat display all active connections, include numeric addresses, and show the process ID owning each connection. This direct mapping allows the responder to identify the exact binary or service responsible for the outbound port 443 traffic, facilitating immediate containment actions against the process.

Why this answer

Identifying the link between network sockets and the system process is critical during incident handling. Netstat or ss utilities, specifically when used with process identification flags, allow responders to map external traffic to local binaries. This visibility is essential for distinguishing between legitimate service communication and unauthorized exfiltration or command-and-control beacons, enabling the responder to terminate malicious processes and isolate affected infrastructure quickly.

Exam trap

Candidates often select packet capture tools or general bandwidth monitors, forgetting that mapping specific ports directly to local process IDs requires endpoint socket utilities.

14
MCQeasy

Which of the following is a primary benefit of using a centralized log management (CLM) solution during an incident?

A.It automatically blocks all malicious traffic.
B.It provides a unified view for log correlation.
C.It encrypts all data on the network.
D.It prevents unauthorized local access.
AnswerB

The main benefit of a CLM solution is its ability to aggregate logs from multiple devices into one searchable interface. This enables analysts to correlate activities, such as matching a network login on a server with an unusual process start on an endpoint, which is essential for investigation.

Why this answer

Centralized log management aggregates logs from disparate sources, providing a single point of visibility. This is crucial for correlation, as it allows analysts to link events across different systems—such as matching a firewall block with a specific endpoint execution. Without CLM, responders must manually query every host, which is slow, error-prone, and often impossible if an attacker deletes local logs to cover their tracks.

Exam trap

Candidates often select answers focused purely on local storage capacity or simple backup solutions, forgetting that incident correlation requires unified multi-source visibility.

15
MCQhard

An incident handler is analyzing a PCAP and observes a series of TCP packets with the SYN flag set, followed by a single RST/ACK packet from the destination. What is the most likely explanation for this pattern?

A.A TCP SYN flood attack is in progress.
B.The source is performing a TCP SYN scan against the destination.
C.The destination host is performing a port scan on the source.
D.A firewall is resetting connections from the source.
AnswerB

In a TCP SYN scan (half-open scan), the scanner sends a SYN packet to a target port. If the port is closed, the target responds with RST/ACK. This pattern is characteristic of tools like Nmap when performing a SYN scan. The scanner does not complete the handshake, making it stealthier. The presence of multiple SYN packets followed by RST/ACK responses indicates that the source is probing multiple ports on the destination.

Why this answer

The sequence of SYN packets followed by RST/ACK responses is indicative of a TCP SYN scan. The scanner sends SYN packets to various ports; if a port is closed, the target replies with RST/ACK. This is a common reconnaissance technique used to discover open ports without completing the TCP handshake.

A SYN flood would not elicit RST/ACK responses, and a firewall reset would typically involve different packet flows. The direction of packets confirms that the source is scanning the destination.

Exam trap

The trap here is confusing a SYN scan with a SYN flood; a SYN flood involves many SYNs without completing handshakes and typically no RST/ACK responses, while a SYN scan receives RST/ACK for closed ports.

16
MCQmedium

An incident handler is examining a web server's access logs after a suspected SQL injection attempt. The log shows a request with a long URL containing multiple single quotes and 'UNION SELECT' statements. Which log field is most critical to correlate this request with other events to determine if the attack succeeded?

A.The HTTP status code
B.The source IP address and timestamp
C.The User-Agent string
D.The requested URL path
AnswerB

The source IP address and timestamp provide a unique combination that can be used to correlate the web request with other log sources, such as database logs, firewall logs, or authentication logs. This allows the incident handler to trace the attacker's actions across multiple systems and determine if the SQL injection led to further compromise.

Why this answer

Correlating events across disparate logs requires a common identifier such as source IP and timestamp. These fields allow the incident handler to pivot from the web server log to database logs, firewall logs, or IDS alerts to see if the SQL injection resulted in data extraction, error messages, or additional requests. Other fields like User-Agent or status code may provide context but lack the uniqueness needed for reliable correlation.

Exam trap

The trap here is assuming that the HTTP status code alone can indicate a successful attack, but many SQL injection attempts return 200 OK even when they fail, and status codes are not unique enough for correlation.

17
Multi-Selectmedium

An analyst is investigating a suspected Pass-the-Hash attack within an Active Directory environment. Which TWO Windows Security Event Log IDs should the analyst examine to detect the use of stolen NTLM credential material for lateral movement? (Choose TWO)

Select 2 answers
A.Event ID 4624 (An account was successfully logged on)
B.Event ID 4625 (An account failed to log on)
C.Event ID 4672 (Special privileges assigned to new logon)
D.Event ID 4720 (A user account was created)
E.Event ID 1102 (The audit log was cleared)
AnswersA, C

Event ID 4624 is critical because Pass-the-Hash attacks result in successful authentication sessions without requiring plaintext passwords. Analysts examine the logon type and authentication package fields within this event to identify anomalous network logons utilizing NTLM.

Why this answer

Event ID 4624 records successful logons, and specifying Logon Type 3 (Network) combined with NTLM authentication indicates a potential Pass-the-Hash event when originating from an unusual source. Event ID 4672 details special privileges assigned to new logins, helping verify if the compromised security context obtained administrative privileges across the domain.

Exam trap

Candidates frequently select Event ID 4625, confusing failed logon attempts with the successful authentication events characteristic of valid stolen hash utilization.

18
MCQeasy

Which of the following best describes the purpose of 'flow data' (like NetFlow) during an incident investigation?

A.To capture the full payload content of every packet.
B.To provide a record of who accessed which specific file.
C.To analyze the volume, source, and destination of network traffic.
D.To perform real-time decryption of SSL/TLS traffic.
AnswerC

Flow data is specifically designed to provide summary information about network traffic. This includes the source IP, destination IP, ports, protocol, and the volume of data transferred, which is essential for identifying anomalous communication patterns during a post-incident forensic investigation.

Why this answer

Flow data provides a high-level summary of network communications, including source, destination, ports, and duration. Unlike full packet capture, which is resource-intensive, flow data is lightweight and allows for long-term retention. It is invaluable for reconstructing an attacker's movement across the network and identifying patterns of communication, such as beaconing to C2 servers, even when specific payload contents are not available.

Exam trap

Candidates often confuse flow data with full packet capture (FPC). They incorrectly assume flow data contains the actual payload contents of packets, which it does not; it only provides metadata summary information.

19
MCQhard

An incident handler is triaging a suspected beaconing implant on a Windows workstation. NetFlow records show a repeating outbound connection to the same external IP address every 60 seconds, but the packets are only 200 bytes each, so no payload is captured. The handler wants to confirm the beacon's timing jitter and any command-and-control content without deploying a new agent to the endpoint. Which investigative approach BEST accomplishes this?

A.Export the NetFlow records to a collector and generate a histogram of flow start times to measure the beacon interval precisely.
B.Pull Windows Security event logs for logon type 3 events and correlate their timestamps with the observed outbound connections.
C.Enable full packet capture on the perimeter sensor and filter the traffic by the destination IP address, then analyze inter-arrival times and payload content.
D.Run a port scan against the external IP address from the workstation to identify the listening service and infer the implant family.
AnswerC

Full packet capture at the perimeter preserves both the timing of each connection and the payload bytes, allowing the handler to calculate beacon jitter and inspect command-and-control content. Filtering by the known destination IP keeps the capture volume manageable. Because no endpoint agent is installed, this satisfies the requirement without touching the host.

Why this answer

Perimeter full packet capture retains both timing and payload, which are exactly the two data points needed to characterize the beacon. Flow records and host logs provide timing or authentication context but never the command-and-control content. Scanning the adversary infrastructure is intrusive and yields no information about the local implant's behavior, so it does not meet the investigative requirement.

Exam trap

The trap here is assuming that flow records contain enough detail to characterize beaconing, when they actually omit payload and sub-second precision.

20
MCQeasy

An incident handler is analyzing a packet capture and notices a high volume of TCP SYN packets sent to multiple ports on a single target host, with no corresponding SYN-ACK responses. The source IP is spoofed. What type of activity does this indicate?

A.Port scanning
B.ARP spoofing
C.UDP fragmentation attack
D.TCP SYN flood
AnswerD

A TCP SYN flood is a denial-of-service attack where the attacker sends numerous SYN packets, often with spoofed source IPs, to exhaust the target's connection table. The lack of SYN-ACK responses is typical because the target is either overwhelmed or the spoofed IPs do not complete the handshake. This matches the scenario exactly.

Why this answer

The combination of numerous TCP SYN packets, spoofed source IP, and absence of SYN-ACK responses is a hallmark of a SYN flood attack. This type of denial-of-service attempts to exhaust the target's resources by leaving half-open connections. Recognizing this pattern helps responders mitigate by enabling SYN cookies or rate limiting.

Exam trap

The trap here is confusing a SYN flood with a port scan; both use SYN packets, but a flood uses spoofed IPs and no responses, while a scan seeks responses to map services.

21
MCQhard

During a network investigation, an incident responder notices a high volume of outbound DNS queries to a single external domain, with each query containing a long, random-looking subdomain. The queries occur at regular intervals of approximately 30 seconds. Which type of attack is most likely indicated?

A.DNS tunneling for data exfiltration
B.DNS amplification attack
C.DNS cache poisoning
D.Fast flux DNS
AnswerA

DNS tunneling for data exfiltration encodes data in DNS queries and responses, often using long, random-looking subdomains to carry the payload. The high volume and regular interval indicate automated beaconing or data transfer. This method bypasses many firewalls because DNS is often allowed outbound, making it a stealthy exfiltration channel.

Why this answer

The combination of high volume, long random subdomains, and regular intervals strongly suggests DNS tunneling for data exfiltration. Attackers use this technique to encode stolen data into DNS queries, which are often allowed through firewalls. The regular interval indicates automated beaconing or a scheduled exfiltration process.

Other DNS-based attacks like cache poisoning or amplification would present different traffic patterns, such as spoofed source IPs or redirection of legitimate queries.

Exam trap

The trap here is confusing DNS tunneling with fast flux; fast flux changes IP addresses rapidly but does not involve encoding data in subdomains, and it typically does not generate such a high volume of queries from one host.

Ready to test yourself?

Try a timed practice session using only Network and Log Investigations questions.