ISC2 Systems Security Certified Practitioner (SSCP) Practice Question
During an investigation you observe a finance server issuing hundreds of DNS requests per minute to exfil.example.net. Each query includes a long base64-like string in the subdomain (e.g., dXNlcmRhdGE=.exfil.example.net) and the replies are TXT records. The firewall allows only ports 53 and 443 outbound, and proxy logs show no large HTTPS transfers. Which data-theft technique is most likely in use?
Exfiltration through DNS tunneling that embeds data in query and TXT record payloads
Embedding sensitive data inside TLS certificate fields sent over HTTPS
Steganography by hiding files inside outbound JPEG images delivered over HTTP
Covert timing channel that hides data in TCP ACK sequence numbers
The pattern of numerous DNS lookups whose query names carry long, encoded strings-combined with TXT record responses-matches DNS tunneling. In this technique, attackers embed chunks of data inside the hostname portion of a DNS query or inside TXT responses, allowing them to slip information past egress controls that permit only DNS traffic. The other options do not rely on DNS traffic: covert channels in TCP ACK fields would appear in TCP sessions, steganography over HTTP would produce HTTP traffic containing images, and exfiltration via TLS certificates would still require outbound HTTPS connections visible in proxy logs.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is DNS tunneling and how does it work?
Open an interactive chat with Bash
Why do attackers use DNS tunneling for data exfiltration instead of other methods?
Open an interactive chat with Bash
How can organizations detect and prevent DNS tunneling attacks?
Open an interactive chat with Bash
ISC2 Systems Security Certified Practitioner (SSCP)
Systems and Application Security
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99 $11.99
$11.99/mo
Billed monthly, Cancel any time.
$19.99 after promotion ends
3 Month Pass
$44.99 $26.99
$8.99/mo
One time purchase of $26.99, Does not auto-renew.
$44.99 after promotion ends
Save $18!
MOST POPULAR
Annual Pass
$119.99 $71.99
$5.99/mo
One time purchase of $71.99, Does not auto-renew.
$119.99 after promotion ends
Save $48!
BEST DEAL
Lifetime Pass
$189.99 $113.99
One time purchase, Good for life.
Save $76!
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .