GCIH Practice Question: Detecting Exploitation and Covert Communication Tools
During an incident response engagement, you observe that a compromised Windows workstation periodically sends DNS queries for subdomains of 'sync.update-service.com', such as 'a1b2c3.sync.update-service.com'. The queries occur at irregular intervals, and the responses contain TXT records with long, high-entropy strings. The domain is not associated with any known legitimate service. Which technique is the adversary most likely using?
⚠ Common exam trap
The trap here is assuming any suspicious DNS traffic is domain fronting or fast flux, when the presence of TXT records and encoded subdomains specifically points to DNS tunneling.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
DNS tunneling for command and control
The adversary is using DNS tunneling to encapsulate command and control data within DNS queries and responses. The high-entropy TXT records and irregular subdomain queries indicate encoded data being sent to and from the attacker's authoritative DNS server. This technique bypasses many network controls because DNS is often allowed outbound.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Fast flux DNS to evade blocklists
Why it's wrong here
Fast flux involves rapidly changing DNS A records for a domain to multiple IP addresses, often to evade IP-based blocking. The scenario describes TXT records and high-entropy subdomains, not rapidly changing A records, so fast flux is not the primary technique observed.
- ✗
Domain fronting to hide C2 traffic
Why it's wrong here
Domain fronting involves using a legitimate CDN domain in the TLS SNI while the HTTP Host header points to a different domain, making traffic appear to go to a trusted service. Here, the domain itself is suspicious and not a known CDN, and the use of TXT records is not typical of domain fronting, which relies on HTTPS.
- ✓
DNS tunneling for command and control
Why this is correct
The use of TXT records with high-entropy data and irregular query timing to a suspicious domain is characteristic of DNS tunneling, where data is encoded in DNS queries and responses to establish a covert channel. The subdomain labels likely carry encoded commands or exfiltrated data, and the TXT responses deliver instructions or acknowledgments.
- ✗
DNS cache poisoning to redirect traffic
Why it's wrong here
DNS cache poisoning involves injecting false DNS records into a resolver's cache to redirect legitimate traffic to malicious IPs. The scenario shows the client querying a suspicious domain directly, not a redirection of legitimate domain resolutions, and the TXT records suggest data transfer rather than poisoning.
Visual reference
About these practice questions
This GCIH question is part of Courseiva's 322-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.