ETExamTower
Q16Network Security

How is DNS tunneling employed to exfiltrate data from a corporate network?

← → navigate · a answer
Community votes
B
82% (9)
C
18% (2)
A
0% (0)
D
0% (0)
Discussion · 19
B 8
Selected Answer: B I would pick B, based on the question. because we are asked how DNS tunneling is used, and the attacker encodes text information in base64 and then sends it to the malicious DNS server mentioned at the end of the question (DNS server rebuilds the exfiltrated data) "C" does not explain how the information is encoded.
5
B. It encodes the payload with random characters that are split into short strings and the DNS server rebuilds the exfiltrated data DNS Tunneling is a technique used to exfiltrate data out of a corporate network by encoding the payload with random characters that are split into short strings and then sending these strings as DNS queries. These queries are sent to a domain controlled by the attacker, which then rebuilds the exfiltrated data. This technique takes advantage of the fact that many corporate networks allow outgoing DNS queries, while other types of traffic may be blocked. Option A, It leverages the DNS server by permitting recursive lookups to spread the attack to other DNS servers, is not really how DNS Tunneling works, it's more about encoding data into DNS queries and exfiltrating it through this channel.
2
Im leaning more toward C in this case. Is the point of the DNS attack not to redirect the victim to a server and then try to steal data?
B 2
Selected Answer: B Once the needed data is obtained, the payload encodes the data as a series of 32 characters broken into short strings... The issue with answer C, is that this not only to get credentials
2
B is false imo - "It encodes the payload with RANDOM characters..." - What is the point of exfiltrating random characters?
C 2
Selected Answer: C This is C
B 2
Selected Answer: B From Cisco's official 350-701 course:- "Most commonly, the data being tunneled out over DNS will be encoded by the attacker to avoid detection. Two of the common encoding methods include Base32 and Base64 encoding"
1
me too
C 1
Selected Answer: C C should be the correct answer. for more inforwation watch this short vid https://www.paloaltonetworks.com/cyberpedia/what-is-dns-tunneling
1
Actually jaciro11 is right, C is correct, but the keyword "redirrect" makes it incorrect as the information is exfiltrated by being encoded in base64
1
Option C, It redirects DNS requests to a malicious server used to steal user credentials, which allows further damage and theft on the network, is not really how DNS Tunneling works. This technique is more about exfiltrating data, not stealing credentials. Option D, It corrupts DNS servers by replacing the actual IP address with a rogue address to collect information or start other attacks, is not really how DNS Tunneling works. DNS Tunneling is more about exfiltrating data, not corrupting DNS servers.
1
I think the correct answer is C. B - "It encodes the payload with RANDOM characters..." There is no sense in exfiltrating random data..
B 1
Selected Answer: B The DNS server cannot rebuild information.
1
Well, for me it really depends on whether these answers are actually worded like this. If so, then B cannot be correct, because DNS servers do not rebuild information (DNS server's role is to handle DNS queries and responses). Option C seems to be the most logical, since the data is encoded, then the encoded payload is inserted into DNS queries and manipulated DNS packets are sent to a malicious DNS server controlled by the attacker. I think I will go with answer C because of that.
B 1
Selected Answer: B B is correct
B 1
Selected Answer: B Maybe it's just me, but I can't see how "redirection" would fit here. "attackers use the DNS protocol to embed data within packets in DNS queries", and get the data shipped out to the attackers DNS server. (not redirecting, just directing it to the malicious server) The data needs to be broken into smaller chunks (to be protocol conform), and is often encoded with base64. https://www.akamai.com/glossary/what-is-dns-data-exfiltration https://bluegoatcyber.com/blog/dns-exfiltration-with-base64-encoding-a-stealthy-data-theft-technique/ I vote for B.
B 1
Selected Answer: B Attackers can use outbound DNS requests to send encoded exfiltrated data to their infrastructure. The DNS tunneling client malware on the infected machine reads the data to be exfiltrated line by line, slices the data into small chunks and performs base64 encoding on each line. So, option B is the closest to describing how DNS tunneling is used to exfiltrate data out of a corporate network.
1
The answer is B.
B 1
Selected Answer: B Correct answer is B