Triage BoardGet the app

Concept · Indicators of malicious activity

DNS tunneling vs DGA vs fast flux

DNS tunneling hides data inside DNS queries and answers, a domain generation algorithm (DGA) lets malware compute a fresh list of domain names to find its server, and fast flux keeps one malicious domain alive by rotating the IP addresses behind it. All three are network clues in indicators of malicious activity (objective 1.2 of the CS0-004 exam), and the exam tells them apart by what changes in the query log: the payload, the name or the address.

  • Exam code CS0-004
  • Tickets here 8

Three patterns in one query log

What each pattern abuses and how it shows up in Domain Name System (DNS) records
PointDNS tunnelingDGAFast flux
Attacker's goalCarry data or commands through DNSReach command and control without a hard-coded nameKeep one domain reachable when hosts are taken down
What keeps changingThe subdomain labels and the answer contentThe registered domain itselfThe IP addresses behind one fixed name
Query namesLong encoded labels under one parent zoneRandom-looking names across many parent domainsThe same name, asked again and again
Typical answersUnusual record types (TXT, NULL, CNAME) carrying large payloadsMostly NXDOMAIN, then a name that finally resolvesA records with a very short time to live (TTL) and a new set each time
Where you see it bestResolver or Zeek dns.log with query length and typeResolver logs grouped by client hostPassive DNS history for the domain
Blocking one IP addressBarely helps: the host talks to your own resolverWeak: the next domain lands somewhere elseUseless: the address set has already moved

A variant called double flux rotates the domain's name server records as well as its A records.

Spot all three in ten lines

zeekFictional resolver log, trimmed to time, client, query, type, result, TTL and answer
10:41:02  10.20.4.17  www.example.com                     A      NOERROR   3600  203.0.113.1010:41:05  10.20.4.31  kq3vz8xw1p.example                  A      NXDOMAIN  -     -10:41:05  10.20.4.31  p0d7mfy2tq.test                     A      NXDOMAIN  -     -10:41:06  10.20.4.31  zt9hb4wc6e.invalid                  A      NXDOMAIN  -     -10:41:07  10.20.4.31  r2xj5nla8u.test                     A      NOERROR   300   198.51.100.7710:41:09  10.20.4.52  nbswy3dpeb3w64tmmq.t.example.net    NULL   NOERROR   0     <binary, 220 bytes>10:41:10  10.20.4.52  mzxw6ytboi4dsnzrgm.t.example.net    CNAME  NOERROR   0     oy5gk3tbmfzq.t.example.net10:41:15  10.20.4.66  shop-deals.example.org              A      NOERROR   60    192.0.2.1410:46:15  10.20.4.66  shop-deals.example.org              A      NOERROR   60    198.51.100.20310:51:15  10.20.4.66  shop-deals.example.org              A      NOERROR   60    203.0.113.91

Lines 2–5: one client walks a list of random names until one resolves (DGA). Lines 6–7: encoded labels under one zone, zero TTL, odd record types (tunneling). Lines 8–10: one name, a new address on every lookup (fast flux). Line 1 is ordinary traffic.

How each one shows up in a question

DNS tunneling: read the shape of the query

Tunneling questions hand you size and shape: query names far longer than anything a browser sends, labels that look like base32 or base64, record types a browser never asks for, and a steady rate from one client to one zone. The trick is to read the parent domain first. Every tunneled query ends in the same zone, because that zone's name server is the attacker's decoder.

The trap is mixing it up with a DGA, since both produce gibberish. Gibberish under one parent domain points to tunneling; gibberish that changes the registered domain points to a DGA.

DGA: count the failures

A DGA runs the same algorithm and seed on the infected host and on the attacker's side. The malware tries every name on the day's list, and the attacker registers only one or two of them, so the client produces a run of failed lookups before a hit. In a question, that pattern belongs to a single internal host.

The usable tip: a blocklist of names you already saw protects you from yesterday's list only. The durable moves are finding the infected host and predicting or sinkholing the names the algorithm will produce next.

Fast flux: watch the answers

In fast flux the name stays put and the answers churn. Dozens of compromised machines take turns answering for the same domain, so each lookup returns a different set of addresses and a TTL measured in seconds or minutes.

The trap is a content delivery network (CDN), which also hands out many addresses with short TTLs. A CDN's addresses belong to the provider's own networks and the domain has a long, boring history; flux addresses scatter across unrelated, often residential networks.

Answers that block an addressTrap

When the stem describes any of these three patterns, an option that only blocks the IP address you just saw is almost always the weak one. The Pyramid of Pain puts IP addresses and domain names near the bottom for a reason: the attacker replaces them in minutes, and two of these patterns exist to do exactly that.

Work the query log

Name the DNS pattern first, then decide what to do about it. The exhibits show one slice of the traffic at a time, so work from what is in front of you.

Ticket 1 / 8

0 right

INC-001

While monitoring network traffic, the security analyst observes the following unusual domain access patterns: What is the most likely explanation for these unusual traffic patterns?

Exhibit

Accessed Domains
abcx.example
efgy.example
ijkz.example
lmnw.example
opqv.example
rstt.example
uvww.example
xyzu.example

Pick an option to open the notes on all of them.

Key and notes on every option

Key: D

  1. ABGP is the routing protocol between networks on the internet and has nothing to do with clients looking up machine-generated domain names.
  2. BA remote access trojan might use a DGA to find its controller, but RAT names a type of malware, not the domain pattern shown.
  3. CMTD is a defensive technology (moving target defense or mobile threat defense), not a pattern of suspicious domain lookups.
  4. DCorrect: Many lookups of similar, machine-generated names that follow one pattern is the signature of a domain generation algorithm, which malware uses to find its command-and-control server.

INC-002

A workstation generated a burst of NXDOMAIN responses followed by several successful resolutions. Which pivot sequence most effectively identifies related compromise artifacts?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: D

  1. AVulnerability scans and patch status describe exposure but cannot say which process made the suspicious lookups or where they led.
  2. BEmail headers and registry keys have no link to the DNS pattern, so this pivot chain drifts away from the evidence.
  3. CAsset inventory and backup logs describe the host, but they do not trace the lookups to a process or to attacker infrastructure.
  4. DCorrect: Pivoting from the process that made the queries to its DNS history and then enriching the resolved IPs ties the NXDOMAIN burst, typical of DGA malware, to the responsible binary and the C2 infrastructure it reached.

INC-003

Which hunt query parameters best detect DGA activity while balancing noise versus sensitivity?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: A

  1. ACorrect: High entropy in domain names combined with many unique, never-seen names is what sets DGA traffic apart, and requiring both signals keeps noise from legitimate random-looking names down.
  2. BQuery volume alone is noisy, because busy hosts and normal applications also generate many DNS queries.
  3. CShort TTLs are common on CDNs and point toward fast-flux rather than DGA, so alerting on all of them floods analysts.
  4. DByte counts from one host suggest data transfer or tunneling, which is a different signal from algorithmically generated domain names.

INC-004

DNS logs show repeated long TXT queries and large responses from one host. Which conclusion is most likely?

Exhibit

TimestampQuery Name LengthResponse SizeClient Process
14:02:11187 chars1240 bytesunknown.exe
14:02:41192 chars1310 bytesunknown.exe
14:03:12179 chars1198 bytesunknown.exe
14:03:43195 chars1285 bytesunknown.exe

Pick an option to open the notes on all of them.

Key and notes on every option

Key: B

  1. ANormal resolution uses short names and small A or AAAA answers instead of repeated TXT queries of about 190 characters with large replies.
  2. BCorrect: Long query names, large TXT responses, a steady 30-second rhythm and an unknown process all point to data tunneled through DNS, so the process and the domain should be dealt with.
  3. CNTP runs over UDP port 123 and never travels inside DNS TXT queries.
  4. DA misconfigured forwarder causes failures or loops for many clients, whereas here one unknown process sends long, regular TXT queries.

INC-005

Proxy logs show regular small uploads and DNS shows periodic encoded subdomains. What is the best analytic approach to validate slow exfiltration?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: D

  1. ASlow exfiltration moves data in small pieces, so looking only for large file transfers in proxy logs is exactly how this channel slips past.
  2. BA 30-day byte total blurs a low-and-slow channel into normal traffic and does not tie the uploads to the encoded DNS names.
  3. CAlerting on every DNS query from VPN hosts floods the queue with noise and does not test whether these encoded subdomains carry data.
  4. DCorrect: lining up DNS and proxy timestamps for the same encoded domains ties the two weak signals to one channel and separates covert exfiltration from ordinary periodic traffic.

INC-006

Which host most likely uses a domain-generation algorithm?

Exhibit

HostUnique QueriesNXDOMAIN %Resolved IPs
HostX876212
HostY983
HostZ14514

Pick an option to open the notes on all of them.

Key and notes on every option

Key: C

  1. ANeither HostY nor HostZ shows the DGA signature: both have few unique queries and low NXDOMAIN rates.
  2. BHostY makes only nine unique queries with an 8 percent NXDOMAIN rate, which is ordinary resolver behavior.
  3. CCorrect: HostX queries many unique names and most of them fail with NXDOMAIN, the pattern of malware cycling through generated domains until it finds the few the operator registered.
  4. DHostZ resolves to many IPs, but with few unique queries and almost no NXDOMAIN responses, that looks more like a load-balanced or CDN-hosted service than a DGA.

INC-007

Passive DNS shows many short-lived A records for one domain across diverse global IPs with a two-day-old registration. Which criteria indicate fast-flux rather than CDN behavior?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: B

  1. ACDNs also serve from IP addresses around the world, so geographic spread alone cannot tell fast-flux from a CDN.
  2. BCorrect: Very short TTLs on a domain registered only days ago is a strong fast-flux signal, because CDNs run on long-established domains.
  3. CMany queries from internal hosts show the domain is popular and prove nothing about infrastructure rotating like fast-flux.
  4. DLarge CDNs also return many different IPs, so the count alone does not separate them from fast-flux networks.

INC-008

Which SIEM query best detects rotating DNS answers for fast-flux?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: C

  1. ANXDOMAIN bursts point to DGA activity, while fast-flux domains resolve successfully, just to constantly changing IPs.
  2. BQuery counts per host measure how busy a client is and cannot show whether a domain's answers keep rotating.
  3. CCorrect: Fast-flux shows up as one domain resolving to many distinct IPs in a short time, so counting distinct answers per domain over a window catches it directly.
  4. DExact matches against known bad domains miss new fast-flux domains, while the rotation pattern catches them.

Shift tally

0 / 0

Edge cases in the query log

If one malware family uses more than one of these, which do I answer?

The one the evidence shows. A single family can use all three: a DGA picks the domain, that domain sits on fast-flux hosting, and the same malware tunnels data out over DNS. Answer the behavior in the exhibit instead of guessing the family.

Which tools should I know for this part of CySA+ CS0-004?

Objective 1.3 of the CS0-004 exam objectives (version 2.0, checked October 2026) names packet and network tools such as Wireshark, tcpdump and Zeek, the security information and event management (SIEM) system, and lookup tools like WHOIS. The analysis tools guide covers what each one shows.

Should I treat DNS over HTTPS as DNS tunneling?

No. DNS over HTTPS is a legitimate way to send ordinary lookups to a resolver inside encrypted web traffic. Tunneling abuses DNS records to carry other data. DNS over HTTPS can still hide lookups from your internal resolver logs, which is why many networks control which resolvers clients may use.

Keep the queue going on your phone

Our practice app carries CySA+ questions to your phone, on iPhone and Android.