Practise as: Incident drill · Interview
Live alertSince 01:00, FIN-LT-042 has sent 60,000 TXT queries for random 50-character subdomains of cdn-metrics-sync.com, a domain registered five days ago.
Interview questionWhat does this look like to you, and how do you respond?
- 01 What happened?
- 02 What is the impact?
- 03 What do you do?
What a strong answer covers
Try it out loud first. Then check yourself:
- High-entropy, high-volume TXT queries to a newly registered domain strongly indicate DNS tunneling C2 or exfil
- Contain: isolate FIN-LT-042 and sinkhole or block the domain at internal resolvers and protective DNS
- Estimate data volume from query sizes; decode sample labels if encoding is simple (base32/hex)
- Endpoint triage: find the process issuing queries (Sysmon Event 22), persistence, and initial access vector
- Hunt other hosts querying the domain or similar patterns; check whether finance data was accessed
If the interviewer pushes back
- The resolver logs only show your DNS server as the client. How do you find the real source host?
Go deeper
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.