Courseiva
hardMultiple ChoiceObjective-mapped

ISC2 CC Practice Question: A security analyst investigates a possible data…

A security analyst investigates a possible data exfiltration. The analyst sees a large amount of data being sent to an external IP address at regular intervals. Which of the following is the most likely technique being used?

⚠ Common exam trap

ISC2 often tests DNS tunneling as a data exfiltration technique because candidates may overlook that DNS traffic is commonly allowed through firewalls, making it a stealthy channel compared to other attack methods.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

DNS tunneling

DNS tunneling encodes data within DNS queries and responses, allowing attackers to bypass network security controls by exfiltrating data through UDP port 53, which is often allowed through firewalls. The regular intervals of large data transfers to an external IP address are characteristic of a DNS tunnel, as the attacker segments data into multiple DNS queries to avoid detection.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • DNS tunneling

    Why this is correct

    DNS tunneling encodes data in DNS requests, allowing stealthy exfiltration.

  • SQL injection

    Why it's wrong here

    SQL injection targets databases but does not necessarily result in regular data dumps to an external IP.

  • Phishing

    Why it's wrong here

    Phishing is an initial access method, not data exfiltration.

  • Man-in-the-middle

    Why it's wrong here

    MITM intercepts traffic, but does not typically involve regular large data transfers to an external IP.

Go deeper

Related to this question

About these practice questions

Courseiva writes every CC question from scratch — 976 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.