Soru

Zorluk: OrtaNetwork Security Monitoring and Alerting

An enterprise Security Operations Center (SOC) analyst is reviewing network security monitoring alerts and NetFlow records for an internal workstation. The monitoring tools report suspicious outbound protocol activity originating from the host. Which of the following network security monitoring findings specifically indicate that DNS tunneling is being utilized for data exfiltration? (Select TWO).

  1. A high volume of DNS TXT record queries containing high-entropy, encoded strings directed to an external authoritative name serverCevap
  2. A significant increase in outbound payload data volume transmitted over UDP port 53 compared to established network baselinesCevap
  3. C
    Outbound HTTP GET requests containing SQL command syntax such as UNION SELECT targeted at external web servers
  4. D
    Implementation of an inline perimeter firewall policy blocking all inbound TCP port 80 web traffic across DMZ segments

Cevap

The network monitoring findings that indicate DNS tunneling for data exfiltration are a high volume of DNS TXT record queries containing high-entropy encoded strings directed to an external authoritative name server, and a significant increase in outbound payload data volume transmitted over UDP port 53 compared to established network baselines.
DNS tunneling abuses standard domain name resolution traffic to exfiltrate sensitive data or maintain covert communications. Network security monitoring tools identify this technique by detecting abnormally large outbound payload transfers on UDP port 53 and uncovering repeated DNS TXT requests containing long, high-entropy encoded subdomains destined for untrusted external name servers.

Adım Adım Çözüm

1
Analyze network protocol traffic volume against baseline metrics.
Identify anomalous outbound byte counts originating on UDP port 53.
Standard DNS queries are small in size; a large outbound byte transfer over port 53 indicates data payload encapsulation.
2
Inspect packet payloads and query record types within DNS monitoring logs.
Detect encoded high-entropy subdomain strings in TXT queries sent to external name servers.
Attackers structure exfiltrated data into subdomains resolved by attacker-controlled authoritative name servers to bypass standard egress filtering.

Anahtar Kavram

Detecting DNS tunneling and data exfiltration indicators using network security monitoring analysis
Bu soruyu puanla