nerdexam
EC-Council

312-39 · Question #81

DNS logs in the SIEM show an internal host sending many DNS queries with long, encoded subdomains to an external domain. The queries predominantly use TXT records and occur during off- business hours.

Sign in or unlock 312-39 to reveal the answer and full explanation for question #81. The question stem and answer options stay visible for context.

Security Incident Detection

Question

DNS logs in the SIEM show an internal host sending many DNS queries with long, encoded subdomains to an external domain. The queries predominantly use TXT records and occur during off- business hours. The external domain is newly registered and has no known business association.

Options

  • AMonitoring DNS cache poisoning attempts
  • BDetecting rogue DNS servers within the internal network
  • CIdentifying DNS tunneling for data exfiltration
  • DValidating DNS records for legitimate business operations

Unlock 312-39 to see the answer

You've previewed enough free 312-39 questions. Unlock 312-39 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#DNS tunneling#data exfiltration#SIEM log analysis#TXT records
Full 312-39 Practice