Question 1
Q1A SOC analyst is reviewing NetFlow data from Cisco Secure Network Analytics (formerly Stealthwatch) and observes a sustained, low-volume stream of outbound traffic on TCP port 53 from a database server. This server is not authorized to perform DNS resolution for external domains. The traffic pattern avoids high-volume thresholds that would trigger standard alerts. Which analytic technique is most effective for identifying this potential DNS tunneling activity?
Show answer & explanation
Correct answer: B
Behavioral anomaly detection is the most effective technique in this scenario. It establishes a baseline of normal activity for the database server and flags the new, unauthorized DNS traffic as a deviation, even if it is low-volume. Statistical volume analysis would likely miss this low-and-slow traffic. Signature-based detection is ineffective as DNS tunneling does not have a universal signature. Heuristic analysis of payloads is not possible with NetFlow, which primarily contains metadata.