Câu 46: 312-39V2: Certified SOC Analyst (CSA) v2
DNS logs in the SIEM show an internal host sending many DNS queries with long, encoded subdomains to an external domain. The queries predominantly use TXT records and occur during off-business hours. The external domain is newly registered and has no known business association. Which of the following best explains thi…
Nội dung câu hỏi
DNS logs in the SIEM show an internal host sending many DNS queries with long, encoded subdomains to an external domain. The queries predominantly use TXT records and occur during off-business hours. The external domain is newly registered and has no known business association. Which of the following best explains this behaviour?
Các lựa chọn
Đáp án được giữ gọn theo nhãn A, B, C, D trong phần bình chọn tương tác.
- A. Monitoring DNS cache poisoning attempts
- B. Detecting rogue DNS servers within the internal network
- C. Validating DNS records for legitimate business operations
- D. Identifying DNS tunneling for data exfiltration — đáp án hiện tại
Cộng đồng
0 bình luận công khai. Tên thành viên được ẩn một phần.