What Does Unusual High-Volume Outbound DNS Traffic Indicate?
A security analyst receives alerts about an internal system sending a large amount of unusual DNS queries to systems on the internet over short periods of time during non-business hours. Which of the following is most likely occurring?
Community Votes
100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests your ability to recognize protocol abuse for stealthy data theft, with the common trap being misinterpreting high external traffic as standard malware propagation.
This question identifies DNS tunneling as a covert data exfiltration technique. The community unanimously agrees that abnormal outbound DNS query spikes during off-hours signal an attacker stealing data through a trusted protocol.
Candidates frequently choose worm propagation, assuming that rapid, automated network communication must indicate self-replicating malware. However, worms primarily target local subnets for lateral movement rather than generating massive query volumes directly to external DNS resolvers.
Community Discussion (5 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Correct Answer: Data Exfiltration
High-volume, unusual DNS queries sent to external internet systems during non-business hours are a hallmark of DNS tunneling, a technique used for covert data exfiltration. Attackers encode stolen information within DNS request payloads to bypass firewalls and egress filtering, which typically allow DNS traffic by default. As highlighted in community feedback, DNS is rarely subjected to deep packet inspection, making it an ideal covert channel for moving sensitive data out of a segmented network.Why Other Options Are Incorrect
A. Worm Propagation
Worms focus on lateral movement and scanning internal networks for vulnerable hosts. Their traffic patterns typically involve broadcast storms or targeted scans across local IP ranges, not sustained, high-volume queries directed at external DNS servers.C. Logic Bomb
A logic bomb is a dormant malicious script that executes only when specific conditions are met (e.g., a date threshold). It does not generate continuous external network traffic or interact with internet DNS infrastructure.D. Ransomware
Ransomware prioritizes file encryption and credential harvesting to spread via SMB or remote management tools. While it may communicate with command-and-control (C2) servers, its defining characteristic is mass file modifications and ransom demands, not anomalous DNS query spikes.Key Takeaway
Always correlate protocol behavior with network context. When a standard service like DNS exhibits abnormal outbound volume to external destinations during off-hours, treat it as a potential covert exfiltration channel until proven otherwise.Official Reference
Exam Strategy
When reviewing network alerts, always evaluate the protocol type, destination, and timing together. If a trusted service like DNS shows abnormal outbound volume to external IPs during off-hours, prioritize investigating covert channels like DNS tunneling before assuming traditional malware activity.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →