GSEC Networking and Protocols Practice Question
A security analyst suspects an internal host is communicating with a command-and-control server using DNS tunneling. Which network protocol characteristic should the analyst examine to best identify this malicious behavior?
⚠ Common exam trap
Candidates often look for 'high bandwidth usage'. DNS tunneling is often slow and stealthy; it relies on the content (entropy/record type) rather than large volumes of data.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Unusually high frequency and elevated entropy levels within TXT or subdomain record queries.
DNS tunneling embeds arbitrary data inside standard DNS queries and responses, primarily utilizing TXT, NULL, or subdomains of A records. Analysing query length and entropy helps security professionals detect abnormal payload sizes that deviate from legitimate domain name resolution patterns, protecting enterprise networks from stealthy data exfiltration and C2 channels.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
TCP connection state tables showing persistent half-open sessions on port 53.
Why it's wrong here
Standard DNS primarily operates over UDP port 53 for standard queries and responses, meaning TCP connection states are less indicative of core tunneling activity unless zone transfers occur, making this metric ineffective for spotting high-entropy payload distribution.क्क
- ✓
Unusually high frequency and elevated entropy levels within TXT or subdomain record queries.
Why this is correct
Malicious actors encode stolen data or remote commands within the subdomains of DNS requests or inside TXT records. Inspecting query frequency, length, and entropy reveals the high-density encoded payloads characteristic of modern tunneling tools like Iodine.क्क
- ✗
Frequent receipt of ICMP Destination Unreachable messages indicating blocked UDP traffic.
Why it's wrong here
ICMP Destination Unreachable messages indicate routing or firewall blocks rather than DNS tunneling payloads. While firewalls might block unauthorized ports, examining ICMP error messages fails to reveal the specific data-hiding characteristics inherent to malicious DNS queries.क्क
- ✗
Elevated round-trip time latency on standard HTTP GET requests traversing proxy servers.
Why it's wrong here
Elevated round-trip latency on HTTP GET requests describes web proxy performance, whereas DNS tunnelling hides data in query and response payloads, detectable through unusually long or high-entropy DNS labels and record-type abuse. Latency monitoring is tempting because tunnelling does add overhead, but it is the correct focus for proxy troubleshooting.
Visual reference
About these practice questions
One of 351 original GSEC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.