GCIH Network and Log Investigations Practice Question
During a network investigation, an incident responder notices a high volume of outbound DNS queries to a single external domain, with each query containing a long, random-looking subdomain. The queries occur at regular intervals of approximately 30 seconds. Which type of attack is most likely indicated?
⚠ Common exam trap
A common mix-up: candidates confuse DNS tunneling with fast flux; fast flux changes IP addresses rapidly but does not involve encoding data in subdomains, and it typically does not generate such a high volume of queries from one host.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
DNS tunneling for data exfiltration
The combination of high volume, long random subdomains, and regular intervals strongly suggests DNS tunneling for data exfiltration. Attackers use this technique to encode stolen data into DNS queries, which are often allowed through firewalls. The regular interval indicates automated beaconing or a scheduled exfiltration process. Other DNS-based attacks like cache poisoning or amplification would present different traffic patterns, such as spoofed source IPs or redirection of legitimate queries.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
DNS tunneling for data exfiltration
Why this is correct
DNS tunneling for data exfiltration encodes data in DNS queries and responses, often using long, random-looking subdomains to carry the payload. The high volume and regular interval indicate automated beaconing or data transfer. This method bypasses many firewalls because DNS is often allowed outbound, making it a stealthy exfiltration channel.
- ✗
DNS amplification attack
Why it's wrong here
A DNS amplification attack uses spoofed source IP addresses to send small queries to open DNS resolvers, which then send large responses to a victim, causing a denial-of-service. This scenario involves a single internal host making repeated queries to an external domain, not spoofed queries targeting a victim, so amplification is not indicated.
- ✗
DNS cache poisoning
Why it's wrong here
DNS cache poisoning involves injecting false DNS records into a resolver's cache to redirect legitimate traffic to malicious IP addresses. It typically results in users being directed to incorrect sites, not in a high volume of outbound queries with random subdomains. The regular interval and long subdomains suggest data exfiltration, not cache poisoning.
- ✗
Fast flux DNS
Why it's wrong here
Fast flux DNS involves rapidly changing DNS records to hide malicious servers behind a constantly changing set of IP addresses. It is often used in botnets for resilience, but it does not typically generate a high volume of outbound queries with random subdomains from a single host. The pattern here is more consistent with data encoding in DNS queries.
Visual reference
About these practice questions
Courseiva writes every GCIH question from scratch — 322 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.