nerdexam
Palo_Alto_Networks

ACE · Question #92

Which of the following represents HTTP traffic events that can be used to identify potential Botnets?

The correct answer is D. Traffic from users that browse to IP addresses instead of fully-qualified domain names, traffic to domains that have been registered in the last 30 days. See the full explanation below for the reasoning.

Question

Which of the following represents HTTP traffic events that can be used to identify potential Botnets?

Options

  • ATraffic from users that browse to IP addresses instead of fully-qualified domain names, downloading W32.Welchia.Worm from a Windows share, traffic to domains that have been registered in the last 30 days, downloading executable files from unknown URL's.
  • BTraffic from users that browse to IP addresses instead of fully-qualified domain names, traffic to domains that have been registered in the last 60 days, downloading executable files from unknown URL's.
  • CTraffic from users that browse to IP addresses instead of fully-qualified domain names, traffic to domains that have been registered in the last 60 days, downloading executable files from unknown URL's, IRC-based Command and Control traffic
  • DTraffic from users that browse to IP addresses instead of fully-qualified domain names, traffic to domains that have been registered in the last 30 days.

How the community answered

(22 responses)
  • A
    5% (1)
  • B
    5% (1)
  • C
    9% (2)
  • D
    82% (18)

Community Discussion

No community discussion yet for this question.

Full ACE Practice