ISC2 CC Network Security Practice Question
A security analyst is investigating a suspected data exfiltration incident. The analyst observes that outbound DNS queries from an internal host contain long, random-looking subdomains and occur at a regular interval. The volume of these queries is unusually high. Which technique is most likely being used?
⚠ Common exam trap
The trap here is assuming that because DNS is a legitimate protocol, any DNS traffic is benign, when the pattern of encoded subdomains and regular timing reveals malicious tunneling.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
DNS tunneling for command and control or data exfiltration
The high volume of DNS queries with long, random subdomains sent at regular intervals is a classic indicator of DNS tunneling, where data is encoded in DNS queries to bypass network controls. This technique is commonly used for command and control and data exfiltration. Other DNS-based attacks like amplification or cache poisoning do not produce this pattern.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
DNS tunneling for command and control or data exfiltration
Why this is correct
DNS tunneling encodes data in DNS queries and responses, often using long, encoded subdomains to carry payloads. The regular interval and high volume of random-looking subdomains are characteristic of malware using DNS to exfiltrate data or receive commands, since DNS is often allowed through firewalls. This matches the observed pattern.
- ✗
A cache poisoning attack against the internal DNS resolver
Why it's wrong here
Cache poisoning involves injecting false DNS records into a resolver's cache, often through forged responses. It does not generate a high volume of outbound queries with random subdomains from a single host. The scenario points to a host generating queries, not an attacker manipulating resolver cache entries.
- ✗
A distributed denial-of-service attack using DNS amplification
Why it's wrong here
DNS amplification attacks involve sending queries with spoofed source addresses to open resolvers, causing large responses to flood a victim. The scenario describes outbound queries from an internal host, not a flood of responses to a target. The regular interval and random subdomains do not fit amplification, which typically uses ANY or similar queries to maximize response size.
- ✗
A zone transfer attempt from an internal host
Why it's wrong here
A zone transfer (AXFR) is a single query that retrieves an entire DNS zone and would not produce a steady stream of queries with random subdomains. Zone transfers are typically blocked at the perimeter and would be a one-time event, not a regular interval of queries. The observed behavior is inconsistent with zone transfer attempts.
Go deeper
Related to this question
Learn chapter
Network Security Components and Controls
Key term
DNS
DNS is the system that translates human-friendly domain names like example.com into machine-readable IP addresses so computers can find each other on a network.
Key term
Incident
An incident is a security event that violates an organization's policies or threatens its data, systems, or operations, requiring a structured response.
About these practice questions
Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.