exam questions

Exam 350-701 All Questions

View all questions & answers for the 350-701 exam

Exam 350-701 topic 1 question 21 discussion

Actual exam question from Cisco's 350-701
Question #: 21
Topic #: 1
[All 350-701 Questions]

How does DNS Tunneling exfiltrate data?

  • A. An attacker registers a domain that a client connects to based on DNS records and sends malware through that connection.
  • B. An attacker opens a reverse DNS shell to get into the client's system and install malware on it.
  • C. An attacker sends an email to the target with hidden DNS resolvers in it to redirect them to a malicious domain.
  • D. An attacker uses a non-standard DNS port to gain access to the organization's DNS servers in order to poison the resolutions.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Alee86
Highly Voted 3 years, 3 months ago
Correct Answer A The attacker registers a domain, such as badsite.com. The domain’s name server points to the attacker’s server, where a tunneling malware program is installed. The attacker infects a computer, which often sits behind a company’s firewall, with malware. Because DNS requests are always allowed to move in and out of the firewall, the infected computer is allowed to send a query to the DNS resolver. The DNS resolver is a server that relays requests for IP addresses to root and top-level domain servers. The DNS resolver routes the query to the attacker’s command-and-control server, where the tunneling program is installed. A connection is now established between the victim and the attacker through the DNS resolver. This tunnel can be used to exfiltrate data or for other malicious purposes. Because there is no direct connection between the attacker and victim, it is more difficult to trace the attacker’s computer.
upvoted 17 times
davezz
2 years, 5 months ago
https://www.paloaltonetworks.com/cyberpedia/what-is-dns-tunneling
upvoted 3 times
...
...
ic0deem
Highly Voted 3 years, 3 months ago
None of the answers address the actual question.
upvoted 12 times
...
Marshpillowz
Most Recent 8 months, 3 weeks ago
Selected Answer: A
Answer is A
upvoted 1 times
...
klu16
10 months, 1 week ago
Selected Answer: A
I would also go with answer A.
upvoted 1 times
...
[Removed]
1 year, 4 months ago
Selected Answer: A
A for sure
upvoted 1 times
...
Cokamaniako
1 year, 6 months ago
Selected Answer: A
The attacker registers a domain, such as badsite.com. The domain’s name server points to the attacker’s server, where a tunneling malware program is installed. The attacker infects a computer, which often sits behind a company’s firewall, with malware. Because DNS requests are always allowed to move in and out of the firewall, the infected computer is allowed to send a query to the DNS resolver. The DNS resolver is a server that relays requests for IP addresses to root and top-level domain servers.
upvoted 1 times
...
Brain_Power
1 year, 6 months ago
Selected Answer: B
I think B is the correct
upvoted 1 times
...
sull3y
1 year, 8 months ago
DNS tunneling is a technique used by attackers to exfiltrate data by encoding the data into DNS queries or responses. The attacker creates a covert communication channel between the victim's computer and a server controlled by the attacker. This technique uses the DNS protocol to bypass firewalls and other network security measures. The correct answer is A. An attacker registers a domain that a client connects to based on DNS records and sends malware through that connection. The attacker creates a DNS tunnel by encoding the data in the DNS queries or responses that are sent to the server controlled by the attacker. The server then extracts the data from the queries or responses and sends it to the attacker.
upvoted 4 times
...
Smileebloke
2 years, 8 months ago
Dont think any of the answers are correct, DNS exfil wont deliver malware. Malware will use DNS tunneling to exfil data.
upvoted 9 times
ffsilveira10
1 year, 2 months ago
Perfect, I agree with you
upvoted 1 times
...
...
whiteherondance
3 years ago
Does anyone else think this questions answers have been mixed up with Question 16?
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...