ETExamTower
Q67Network Security

How does DNS tunneling exfiltrate data?

← → navigate · a answer
Community votes
A
80% (4)
B
20% (1)
C
0% (0)
D
0% (0)
Discussion · 11
18
Correct Answer A The attacker registers a domain, like badsite.com. The domain’s name server points to the attacker’s server, where a tunneling malware program is installed. The attacker infects a computer, which is often behind a company’s firewall, with malware. Since DNS requests are always allowed to go in and out of the firewall, the infected computer is allowed to send a query to the DNS resolver. The DNS resolver is a server that relays requests for IP addresses to root and top-level domain servers. The DNS resolver routes the query to the attacker’s command-and-control server, where the tunneling program is installed. A connection is now established between the victim and the attacker through the DNS resolver. This tunnel can then be used to exfiltrate data or for other malicious purposes. Because there is no direct connection between the attacker and victim, it is harder to trace the attacker’s computer.
15
None of the answers really address the actual question.
9
Dont think any of the answers are correct, DNS exfil wont deliver malware. Malware will use DNS tunneling to exfil data.
5
DNS tunneling is a method attackers use to exfiltrate data by encoding it into DNS queries or responses. The attacker sets up a covert communication channel between the victim's computer and a server controlled by the attacker. This technique uses the DNS protocol to get around firewalls and other network security measures. The correct answer is A. An attacker registers a domain that a client connects to based on DNS records and sends malware through that connection. The attacker creates a DNS tunnel by encoding the data in the DNS queries or responses that are sent to the server controlled by the attacker. The server then pulls the data out of the queries or responses and sends it to the attacker.
4
Does anyone else think this question's answers have been mixed up with Question 16?
4
https://www.paloaltonetworks.com/cyberpedia/what-is-dns-tunneling
B 1
Selected Answer: B I think B is the correct one
A 1
Selected Answer: A The attacker registers a domain, such as badsite.com. The domain’s name server points to the attacker’s server, where a tunneling malware program is installed. The attacker infects a computer, which is often behind a company’s firewall, with malware. Since DNS requests are always allowed to move in and out of the firewall, the infected computer is allowed to send a query to the DNS resolver. The DNS resolver is a server that relays requests for IP addresses to root and top-level domain servers.
1
Perfect, I agree with you
A 1
Selected Answer: A I would also pick answer A.
A 1
Selected Answer: A Answer is A