hardMultiple Choice
SSCP Practice Question: A security analyst is investigating a potential…
A security analyst is investigating a potential data exfiltration incident. The logs show a large number of outbound DNS queries to a domain that resolves to an IP address in a foreign country. The queries contain encoded strings in the subdomain. Which type of attack is MOST likely occurring?
⚠ Common exam trap
A common mix-up: candidates confuse DNS tunneling with DNS amplification because both involve high query volumes, but amplification focuses on response size and reflection, not on encoding data in subdomains for exfiltration.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
DNS tunneling
DNS tunneling encodes data within DNS queries and responses to bypass network security controls. The large volume of outbound queries to a foreign IP, combined with encoded subdomain strings, is the classic signature of data exfiltration via DNS tunneling, as the protocol is often allowed through firewalls.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
DNS poisoning
Why it's wrong here
DNS poisoning corrupts resolver cache entries so victims reach attacker-controlled addresses; it does not generate high volumes of encoded subdomain queries. Poisoning fits scenarios where users are silently redirected to fraudulent sites after a cache is compromised.
- ✗
DNS amplification attack
Why it's wrong here
DNS tunnelling exfiltrates data by encoding it in subdomain labels of queries to an attacker-controlled authoritative server; amplification instead spoofs a victim's address to flood it with large responses, and generates no encoded subdomain payloads. Amplification is tempting because it also abuses DNS, but it is a denial-of-service technique, not data theft.
- ✗
DNS rebinding
Why it's wrong here
DNS rebinding manipulates short TTL records so a browser later reaches an internal IP, enabling same-origin access; it produces no encoded subdomain payloads. Rebinding suits bypassing network perimeter controls to reach internal services, not bulk exfiltration.
- ✓
DNS tunneling
Why this is correct
DNS tunneling encodes data in DNS queries and responses for covert exfiltration.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.