300-220 · Question #126
Which of the following is a common method for detecting phishing attacks in threat hunting techniques?
The correct answer is A. DNS monitoring. DNS monitoring is the correct choice because phishing attacks rely on malicious domains, and monitoring DNS queries allows threat hunters to detect unusual domain lookups, newly registered domains, domain generation algorithm (DGA) patterns, and connections to known malicious…
Question
Which of the following is a common method for detecting phishing attacks in threat hunting techniques?
Options
- ADNS monitoring
- BPredictive analytics
- CAsset management
- DHardware encryption
How the community answered
(35 responses)- A94% (33)
- B3% (1)
- D3% (1)
Explanation
DNS monitoring is the correct choice because phishing attacks rely on malicious domains, and monitoring DNS queries allows threat hunters to detect unusual domain lookups, newly registered domains, domain generation algorithm (DGA) patterns, and connections to known malicious infrastructure - all hallmarks of phishing campaigns. Predictive analytics (B) is a data science technique for forecasting future events, not a direct detection method for active threats. Asset management (C) tracks inventory of hardware and software in an environment and has no direct role in identifying phishing activity. Hardware encryption (D) protects data at rest on physical devices and is a data protection control, not a detection technique.
Memory tip: Think "DNS = Domain Name Sleuth" - since phishing lives and dies by its fake domains, watching DNS traffic is how you catch it in the act.
Topics
Community Discussion
No community discussion yet for this question.