What Does Unusual High-Volume Outbound DNS Traffic Indicate?

A security analyst receives alerts about an internal system sending a large amount of unusual DNS queries to systems on the internet over short periods of time during non-business hours. Which of the following is most likely occurring?

  1. A worm is propagating across the network.
  2. Data is being exfiltrated. Source Reference Answer
  3. A logic bomb is deleting data.
  4. Ransomware is encrypting files.

Community Votes

B
100%

100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests your ability to recognize protocol abuse for stealthy data theft, with the common trap being misinterpreting high external traffic as standard malware propagation.

This question identifies DNS tunneling as a covert data exfiltration technique. The community unanimously agrees that abnormal outbound DNS query spikes during off-hours signal an attacker stealing data through a trusted protocol.

Candidates frequently choose worm propagation, assuming that rapid, automated network communication must indicate self-replicating malware. However, worms primarily target local subnets for lateral movement rather than generating massive query volumes directly to external DNS resolvers.

Community Discussion (5 comments)

dbrowndiver 👍 5 Selected: B
The scenario describes an internal system sending unusual and large amounts of DNS queries to external systems, especially during non-business hours. This behavior is indicative of data exfiltration, where an attacker tries to move data out of the network covertly.
MaxiPrince 👍 1 Selected: B
Data is being exfiltrated.
baronvon 👍 4 Selected: B
B. Data is being exfiltrated. A large volume of DNS queries to external systems during non-business hours can indicate that data is being exfiltrated. Attackers often use DNS queries to covertly extract data from compromised systems, as DNS traffic is less likely to be scrutinized compared to other types of network traffic.
Shaman73 👍 2 Selected: B
B. Data is being exfiltrated.
MahiMahiMahi 👍 2 Selected: B
B. Data is being exfiltrated.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Correct Answer: Data Exfiltration

High-volume, unusual DNS queries sent to external internet systems during non-business hours are a hallmark of DNS tunneling, a technique used for covert data exfiltration. Attackers encode stolen information within DNS request payloads to bypass firewalls and egress filtering, which typically allow DNS traffic by default. As highlighted in community feedback, DNS is rarely subjected to deep packet inspection, making it an ideal covert channel for moving sensitive data out of a segmented network.

Why Other Options Are Incorrect

A. Worm Propagation

Worms focus on lateral movement and scanning internal networks for vulnerable hosts. Their traffic patterns typically involve broadcast storms or targeted scans across local IP ranges, not sustained, high-volume queries directed at external DNS servers.

C. Logic Bomb

A logic bomb is a dormant malicious script that executes only when specific conditions are met (e.g., a date threshold). It does not generate continuous external network traffic or interact with internet DNS infrastructure.

D. Ransomware

Ransomware prioritizes file encryption and credential harvesting to spread via SMB or remote management tools. While it may communicate with command-and-control (C2) servers, its defining characteristic is mass file modifications and ransom demands, not anomalous DNS query spikes.

Key Takeaway

Always correlate protocol behavior with network context. When a standard service like DNS exhibits abnormal outbound volume to external destinations during off-hours, treat it as a potential covert exfiltration channel until proven otherwise.

Official Reference

Exam Strategy

When reviewing network alerts, always evaluate the protocol type, destination, and timing together. If a trusted service like DNS shows abnormal outbound volume to external IPs during off-hours, prioritize investigating covert channels like DNS tunneling before assuming traditional malware activity.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide