A Security Operations Center (SOC) analyst investigating a high-severity alert in a SIEM platform correlates the following consecutive syslog entries from an internal recursive DNS resolver:
text
2026-07-27T14:22:01Z dns-resolver named[2048]: client 10.2.14.88#49152 (v1-a8f9c2d1e.exfil.external-collector.net): query: v1-a8f9c2d1e.exfil.external-collector.net IN TXT + (10.2.0.1)
2026-07-27T14:22:02Z dns-resolver named[2048]: client 10.2.14.88#49153 (v2-b7e8d3c4a.exfil.external-collector.net): query: v2-b7e8d3c4a.exfil.external-collector.net IN TXT + (10.2.0.1)
2026-07-27T14:22:03Z dns-resolver named[2048]: client 10.2.14.88#49154 (v3-f5a6b7c8d.exfil.external-collector.net): query: v3-f5a6b7c8d.exfil.external-collector.net IN TXT + (10.2.0.1)
Based on the log attributes, which of the following security events is occurring on host 10.2.14.88?
- DNS tunneling protocol abuse transmitting stolen payload data within encoded domain prefixes and TXT record queriesCevap
- BA Cross-Site Scripting (XSS) exploit attempting to execute client-side scripts inside the DNS server web administration interface
- CA failure in administrative access control where host 10.2.14.88 was authenticated but denied authorization to execute system commands
- DA distributed reflective denial-of-service (DRDoS) attack targeting internal endpoint hosts with amplified response traffic