Courseiva

GCIH Practice Question: Detecting Exploitation and Covert Communication Tools

During an incident response engagement, you observe that a compromised Windows workstation periodically sends DNS queries for subdomains of 'sync.update-service.com', such as 'a1b2c3.sync.update-service.com'. The queries occur at irregular intervals, and the responses contain TXT records with long, high-entropy strings. The domain is not associated with any known legitimate service. Which technique is the adversary most likely using?

⚠ Common exam trap

The trap here is assuming any suspicious DNS traffic is domain fronting or fast flux, when the presence of TXT records and encoded subdomains specifically points to DNS tunneling.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

DNS tunneling for command and control

The adversary is using DNS tunneling to encapsulate command and control data within DNS queries and responses. The high-entropy TXT records and irregular subdomain queries indicate encoded data being sent to and from the attacker's authoritative DNS server. This technique bypasses many network controls because DNS is often allowed outbound.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Fast flux DNS to evade blocklists

    Why it's wrong here

    Fast flux involves rapidly changing DNS A records for a domain to multiple IP addresses, often to evade IP-based blocking. The scenario describes TXT records and high-entropy subdomains, not rapidly changing A records, so fast flux is not the primary technique observed.

  • ✗

    Domain fronting to hide C2 traffic

    Why it's wrong here

    Domain fronting involves using a legitimate CDN domain in the TLS SNI while the HTTP Host header points to a different domain, making traffic appear to go to a trusted service. Here, the domain itself is suspicious and not a known CDN, and the use of TXT records is not typical of domain fronting, which relies on HTTPS.

  • ✓

    DNS tunneling for command and control

    Why this is correct

    The use of TXT records with high-entropy data and irregular query timing to a suspicious domain is characteristic of DNS tunneling, where data is encoded in DNS queries and responses to establish a covert channel. The subdomain labels likely carry encoded commands or exfiltrated data, and the TXT responses deliver instructions or acknowledgments.

  • ✗

    DNS cache poisoning to redirect traffic

    Why it's wrong here

    DNS cache poisoning involves injecting false DNS records into a resolver's cache to redirect legitimate traffic to malicious IPs. The scenario shows the client querying a suspicious domain directly, not a redirection of legitimate domain resolutions, and the TXT records suggest data transfer rather than poisoning.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

This GCIH question is part of Courseiva's 322-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.