GCIH Incident Response and Cyber Investigation Practice Question
During an incident response engagement, the team suspects that an attacker is using DNS tunneling to exfiltrate data. The team captures network traffic and wants to confirm the exfiltration. Which of the following DNS traffic characteristics would MOST strongly indicate DNS tunneling?
⚠ Common exam trap
The trap here is assuming any unusual DNS behavior, like TCP usage or short TTLs, indicates tunneling, when the hallmark is the encoded data in subdomains and high query volume to one domain.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A high volume of DNS queries for a single domain with long, random-looking subdomains.
The strongest indicator of DNS tunneling is a high volume of DNS queries to a single domain with long, random-looking subdomains. This pattern suggests data is being encoded in the subdomain labels and sent to an attacker-controlled authoritative DNS server. Other options, such as queries to legitimate domains or TCP usage, are not specific to tunneling and can occur in normal traffic.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
DNS queries that use TCP instead of UDP on port 53.
Why it's wrong here
DNS over TCP is used for large responses or zone transfers and is not inherently malicious. While some tunneling tools may use TCP, it is not a strong indicator by itself. Many legitimate DNS operations use TCP, such as DNSSEC or when responses exceed 512 bytes. So this alone does not confirm tunneling.
- ✗
DNS responses that contain only A records and have a short TTL.
Why it's wrong here
Short TTLs and A records are common in legitimate DNS, especially for load balancing or dynamic content. They do not indicate tunneling. Tunneling often involves TXT, NULL, or CNAME records to carry data, and may have varying TTLs. The type of record and payload size are more telling than TTL.
- ✓
A high volume of DNS queries for a single domain with long, random-looking subdomains.
Why this is correct
DNS tunneling often involves encoding data in subdomains, resulting in long, random-looking labels. A high volume of queries to a single domain can indicate a covert channel. This pattern is characteristic of tools like iodine or dnscat2, which use DNS to transfer data. The randomness and length are key indicators.
- ✗
Frequent DNS queries to multiple known legitimate domains like google.com and microsoft.com.
Why it's wrong here
Queries to legitimate domains are normal and expected in most networks. While attackers might use domain fronting or compromised legitimate domains, frequent queries to well-known domains are not inherently suspicious. DNS tunneling typically uses a single attacker-controlled domain, not many popular ones.
Visual reference
About these practice questions
Courseiva writes every GCIH question from scratch — 322 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.