Courseiva
Command and Control →mediumMultiple Choice

GPEN Command and Control Practice Question

When evaluating the security of an organization's C2 detection capabilities, which log source is the most valuable for detecting DNS-based C2?

⚠ Common exam trap

Students mistakenly choose endpoint antivirus logs or firewall packet captures, forgetting that DNS traffic happens entirely at the infrastructure level via name resolution.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Centralized DNS query logs.

DNS query logs are the primary data source for identifying DNS-based C2. By analyzing these logs, security teams can identify anomalies such as high volumes of queries to a specific domain, unusual record types like TXT or NULL records, or domains with extremely high entropy. Without centralized DNS logging, detecting this specific type of C2 becomes nearly impossible, as the traffic occurs at the infrastructure level rather than the end-host level.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Endpoint system event logs.

    Why it's wrong here

    While system event logs might show process execution or network connections, they do not provide the granular view of DNS resolution requests needed to identify DNS tunneling. DNS queries are handled by system libraries and forwarded to resolvers, so the actual query details are not captured in standard process logs.

  • ✓

    Centralized DNS query logs.

    Why this is correct

    DNS logs contain the full query history, including the requested domain names and the record types used. This is the most effective data source for detecting DNS tunneling, as it allows analysts to perform statistical analysis and identify patterns indicative of covert channels and malicious name resolution.

  • ✗

    Firewall traffic logs (Layer 4).

    Why it's wrong here

    Firewall logs generally only capture source/destination IP and port information. Since DNS traffic uses port 53, firewall logs will show a high volume of traffic to a DNS server, but they lack the visibility into the DNS query content itself, which is essential for identifying tunneling.

  • ✗

    Antivirus detection logs.

    Why it's wrong here

    Antivirus logs are reactive and depend on signatures or behavioral heuristics that might not be tuned for DNS tunneling. If the malware is novel, the AV will not have a signature for it, and the DNS traffic itself will continue to be ignored by the AV software.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

One of 298 original GPEN practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.