Courseiva

GCIH Practice Question: Detecting Evasive and Post-Exploitation Techniques

During an incident response engagement, an analyst observes that a Windows workstation is making DNS queries for a domain that resolves to an IP address owned by a cloud provider. The queries are for subdomains that appear randomly generated and change frequently. The workstation also has periodic HTTPS connections to that IP. The analyst suspects domain fronting. Which of the following best describes how domain fronting is used in this scenario?

⚠ Common exam trap

The trap here is assuming that random DNS queries and HTTPS traffic indicate DNS tunneling or fast-flux, when the defining characteristic of domain fronting is the use of a legitimate front domain with a mismatched Host header.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The attacker sends traffic to a legitimate domain's IP but uses a different Host header to reach the actual command-and-control server.

Domain fronting allows an attacker to hide command-and-control traffic by connecting to a legitimate domain's IP address while specifying a different Host header that routes to the attacker's server. This makes the traffic appear to go to a trusted domain, evading network filters. The random subdomains and periodic HTTPS connections are consistent with this technique.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The attacker sends traffic to a legitimate domain's IP but uses a different Host header to reach the actual command-and-control server.

    Why this is correct

    Domain fronting exploits the difference between the DNS name and the HTTP Host header. The client connects to a legitimate domain's IP (the front), but the Host header specifies the actual malicious domain. The front server, often a CDN, routes the request based on the Host header. This allows the attacker to blend in with traffic to a reputable domain, bypassing network filters.

  • ✗

    The attacker compromises a legitimate website and uses it to host malicious payloads.

    Why it's wrong here

    This describes a watering hole or compromised website attack, not domain fronting. Domain fronting does not require compromising the front domain; it leverages the domain's infrastructure, such as a CDN, to relay traffic. The attacker does not need to control the front domain's content. Therefore, this option is incorrect.

  • ✗

    The attacker uses a fast-flux network to rapidly change DNS records and evade detection.

    Why it's wrong here

    Fast-flux involves rapidly changing DNS A records to multiple compromised hosts, often used for resilience. Domain fronting, in contrast, uses a stable front domain and manipulates the Host header. The random subdomains in the scenario might suggest fast-flux, but the key indicator is the mismatch between the front domain and the actual C2, which is domain fronting.

  • ✗

    The attacker uses DNS tunneling to exfiltrate data through the DNS queries.

    Why it's wrong here

    DNS tunneling involves encoding data in DNS queries and responses, often using TXT records. In domain fronting, the DNS queries themselves are not used to carry data; they simply resolve the front domain. The actual malicious traffic is in the HTTPS connection to the same IP but with a different Host header. Therefore, this option mischaracterizes the technique.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

Courseiva writes every GCIH question from scratch — 322 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.