Which THREE techniques would you use in Microsoft Sentinel to hunt for data exfiltration over DNS?
DNS tunneling commonly encodes data in the subdomain portion of a query name, so attackers craft unusually long subdomains (often 50+ characters) and generate a high query volume to a single authoritative domain. By analyzing DNS query logs for these patterns—such as label length, entropy, and query frequency per domain—you can directly detect the covert channel. This technique is effective because DNS traffic is frequently allowed through firewalls without deep inspection, making the logs the primary evidence of the exfiltration.
Why this answer
Option A is correct because DNS tunneling and exfiltration typically manifest as unusually high query volumes to a single domain or abnormally long subdomain labels that encode stolen data, so analyzing DNS query logs for these patterns is a core hunting technique in Microsoft Sentinel. Option C is correct because correlating DNS events with process creation events (for example via SecurityEvent 4688 or Sysmon Event ID 1) lets you identify which executable or script is generating the suspicious queries, distinguishing malicious tooling from legitimate resolvers. Option E is correct because ASIM (Advanced Security Information Model) DNS parsers normalize DNS logs from multiple sources into a common schema, enabling consistent anomaly detection and cross-source correlation across the workspace.
Option B is not part of DNS exfiltration hunting since it focuses on large transfers to cloud storage IPs, which is HTTP/HTTPS exfiltration rather than DNS-based. Option D is also unrelated, as email forwarding rules address exfiltration via email (for example Exchange transport rules) and not DNS tunneling.