Courseiva
Network Security →mediumMultiple Choice

ISC2 CC Network Security Practice Question

A security analyst is investigating a suspected data exfiltration incident. The analyst observes that outbound DNS queries from an internal host contain long, random-looking subdomains and occur at a regular interval. The volume of these queries is unusually high. Which technique is most likely being used?

⚠ Common exam trap

The trap here is assuming that because DNS is a legitimate protocol, any DNS traffic is benign, when the pattern of encoded subdomains and regular timing reveals malicious tunneling.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

DNS tunneling for command and control or data exfiltration

The high volume of DNS queries with long, random subdomains sent at regular intervals is a classic indicator of DNS tunneling, where data is encoded in DNS queries to bypass network controls. This technique is commonly used for command and control and data exfiltration. Other DNS-based attacks like amplification or cache poisoning do not produce this pattern.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    DNS tunneling for command and control or data exfiltration

    Why this is correct

    DNS tunneling encodes data in DNS queries and responses, often using long, encoded subdomains to carry payloads. The regular interval and high volume of random-looking subdomains are characteristic of malware using DNS to exfiltrate data or receive commands, since DNS is often allowed through firewalls. This matches the observed pattern.

  • ✗

    A cache poisoning attack against the internal DNS resolver

    Why it's wrong here

    Cache poisoning involves injecting false DNS records into a resolver's cache, often through forged responses. It does not generate a high volume of outbound queries with random subdomains from a single host. The scenario points to a host generating queries, not an attacker manipulating resolver cache entries.

  • ✗

    A distributed denial-of-service attack using DNS amplification

    Why it's wrong here

    DNS amplification attacks involve sending queries with spoofed source addresses to open resolvers, causing large responses to flood a victim. The scenario describes outbound queries from an internal host, not a flood of responses to a target. The regular interval and random subdomains do not fit amplification, which typically uses ANY or similar queries to maximize response size.

  • ✗

    A zone transfer attempt from an internal host

    Why it's wrong here

    A zone transfer (AXFR) is a single query that retrieves an entire DNS zone and would not produce a steady stream of queries with random subdomains. Zone transfers are typically blocked at the perimeter and would be a one-time event, not a regular interval of queries. The observed behavior is inconsistent with zone transfer attempts.

About these practice questions

Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.