A SOC analyst reviewing DNS logs sees many unusually long DNS queries, including TXT and subdomain records, sent to rarely seen domains from several workstations. The queries increase after file transfer activity. Which indicator best matches this pattern?
Select an answer to reveal the explanation.
Short Explanation
Think about DNS as a normal phone directory: if every query suddenly looks like a long encoded note to weird domains, something is hiding in the traffic. You’re seeing DNS tunneling or covert channeling, not just noisy lookups. Don’t chase every high-volume DNS alert; check the query shape, record type, and timing around file transfers.
Full Explanation
The pattern points to DNS tunneling or covert channeling because attackers can encode payloads into DNS queries, especially long subdomains or TXT records, and send them to attacker-controlled or rarely seen domains. This technique can exfiltrate data or carry C2 instructions while blending into normal DNS traffic. A DNS cache poisoning attack is wrong because it involves corrupting resolver records to redirect legitimate lookups, not sending encoded queries to rare domains. A resolver misconfiguration causing recursive query loops is wrong because it typically produces repeated internal queries, loop errors, or broken resolution, not long encoded payloads tied to file transfers. A DNS amplification DDoS attack is wrong because it abuses spoofed queries with large responses to flood a victim, not covertly moving data from internal hosts to unusual domains. Exam caveat: Do not stop at high volume; judge the query content, record type, entropy, destination reputation, and timing around suspicious activity. Operational check: Pivot to full packet capture or DNS query strings, compare against known-good baseline, and block or sinkhole the suspicious domains while preserving evidence.