nerdexam
EC-Council

312-85 · Question #44

Enrage Tech Company hired Enrique, a security analyst, for performing threat intelligence analysis. While performing data collection process, he used a counterintelligence mechanism where a…

The correct answer is B. Data collection through DNS interrogation. Option B is correct because DNS interrogation, as described in this scenario, involves deploying a recursive DNS server specifically as a counterintelligence mechanism that intercepts and logs DNS responses during interserver communication, then replicates that logged data to a…

Threat Intelligence Feeds and Sources

Question

Enrage Tech Company hired Enrique, a security analyst, for performing threat intelligence analysis. While performing data collection process, he used a counterintelligence mechanism where a recursive DNS server is employed to perform interserver DNS communication and when a request is generated from any name server to the recursive DNS server, the recursive DNS servers log the responses that are received. Then it replicates the logged data and stores the data in the central database. Using these logs, he analyzed the malicious attempts that took place over DNS infrastructure. Which of the following cyber counterintelligence (CCI) gathering technique has Enrique used for data collection?

Options

  • AData collection through passive DNS monitoring
  • BData collection through DNS interrogation
  • CData collection through DNS zone transfer
  • DData collection through dynamic DNS (DDNS)

How the community answered

(38 responses)
  • A
    16% (6)
  • B
    71% (27)
  • C
    5% (2)
  • D
    8% (3)

Explanation

Option B is correct because DNS interrogation, as described in this scenario, involves deploying a recursive DNS server specifically as a counterintelligence mechanism that intercepts and logs DNS responses during interserver communication, then replicates that logged data to a central database for analysis - precisely the workflow Enrique followed to identify malicious activity across the DNS infrastructure.

Option A (Passive DNS Monitoring) is wrong because passive DNS is a network-sensor-based approach that captures DNS traffic at the packet level without deploying a dedicated recursive resolver as the interrogation point; it doesn't emphasize the recursive server's active role in logging interserver request/response cycles and replicating them centrally.

Option C (DNS Zone Transfer) is wrong because zone transfers (AXFR requests) are a DNS administration mechanism for replicating zone records between primary and secondary name servers - they're used as a reconnaissance technique against targets, not as a CCI logging/monitoring setup.

Option D (Dynamic DNS / DDNS) is wrong because DDNS is a service that automatically updates DNS records when IP addresses change - attackers use it to maintain C2 infrastructure, but it is not a data collection or monitoring technique at all.

Memory tip: Link "interrogation" to "placing an informant inside the conversation" - DNS interrogation puts a recursive server inside the DNS communication path to listen and record what name servers are saying to each other, just like an interrogator embedded in a conversation.

Topics

#DNS monitoring#threat intelligence sources#DNS logs#counterintelligence

Community Discussion

No community discussion yet for this question.

Full 312-85 Practice