GSEC Networking and Protocols Practice Question
A network security team is reviewing how name resolution traffic can be abused. An analyst notes that a compromised host is generating a high volume of DNS queries for long, random-looking subdomains under a single external domain, and responses contain similarly encoded data. The team wants to classify this activity and describe the underlying mechanism. Which statement best characterizes what is occurring?
⚠ Common exam trap
The trap here is labeling any abusive DNS traffic as cache poisoning or amplification when the bidirectional, encoded query pattern uniquely indicates tunneling.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
DNS tunneling, where data and commands are encoded into DNS queries and responses to create a covert channel.
Encoding data into DNS query names and response records creates a covert channel known as DNS tunneling. High-entropy subdomain labels and a sustained query volume toward one external domain are the hallmarks. The resolver forwards queries to the attacker's authoritative server, which returns encoded responses. This differs from zone transfers, cache poisoning, and amplification, which have distinct traffic signatures and objectives.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A DNS amplification attack, where spoofed queries generate large responses aimed at a victim.
Why it's wrong here
DNS amplification spoofs the source address of queries so that large responses are directed at a third-party victim, multiplying bandwidth. It originates from many reflectors and targets one victim, not from a single internal host maintaining an ongoing dialogue with one domain. The scenario involves bidirectional encoded exchanges from a compromised internal host, which is tunneling rather than reflection-based amplification.
- ✗
DNS cache poisoning, where forged responses insert malicious records into a resolver's cache.
Why it's wrong here
Cache poisoning injects false records so subsequent lookups return attacker-controlled addresses, usually with a small number of forged responses targeting a specific victim record. It does not involve a sustained high volume of unique encoded subdomains from one host. The described pattern is continuous bidirectional data exchange, characteristic of tunneling, whereas poisoning is a discrete redirection attack affecting other clients' resolutions.
- ✓
DNS tunneling, where data and commands are encoded into DNS queries and responses to create a covert channel.
Why this is correct
DNS tunneling encodes arbitrary payloads into query names and response records, using the resolver as a transport to an attacker-controlled authoritative server. Long, high-entropy subdomain labels and a high volume of queries to one domain are classic indicators. Because DNS is rarely blocked, this technique lets a compromised host exfiltrate data and receive commands while blending into normal resolution traffic.
- ✗
A zone transfer abuse, where the attacker pulls the entire DNS zone from an authoritative server.
Why it's wrong here
Zone transfers use AXFR or IXFR over TCP and copy a full zone from an authoritative server, typically producing one large synchronous response rather than a sustained stream of many small queries. The scenario shows continuous query-response pairs with encoded labels, which is bidirectional tunneling. Zone transfer abuse is a reconnaissance and data-exposure issue, not a covert command-and-control channel, so this classification is incorrect.
Visual reference
About these practice questions
This GSEC question is part of Courseiva's 351-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.