During a corporate data breach investigation, investigators identify exfiltration via DNS tunneling. What characteristic best identifies DNS tunneling activity in log analysis?
-
A
Unusually large number of HTTPS GET requests to known CDNs
-
B
Abnormally long or high-frequency DNS queries to a single external domain
-
C
Multiple failed authentication attempts on the VPN gateway
-
D
Large ICMP packet sizes from internal workstations