A SOC analyst notices that an internal host is sending DNS queries to an external server every 60 seconds with unusually long subdomains. What attack technique does this most likely indicate?
-
A
DNS amplification attack
-
B
DNS tunneling for C2 communication
-
C
DNS cache poisoning
-
D
DNS zone transfer abuse