CAS-005 · Question #119
A security analyst reviews network logs and notices a large number of domain name queries originating from an internal server for an unknown domain, similar to the following…
The correct answer is A. Check for data exfiltration. A high volume of DNS queries to unknown domains may indicate domain generation algorithm (DGA) activity associated with malware. Checking for data exfiltration is the next logical step to determine if sensitive data is being leaked to these domains. Reconfiguring DNS settings…
Question
A security analyst reviews network logs and notices a large number of domain name queries originating from an internal server for an unknown domain, similar to the following:
2736287327321782.hgQ43jsi23-y.com 0357320932922C91.hgQ43jsu23Ty.com 4042301801399103.hgQ43jsu23Ly.com Which of the following should the analyst do next?
Options
- ACheck for data exfiltration.
- BReconfigure the server's DNS settings.
- CBrowse for a website on the requested domain.
- DAdd the host names to a block list.
How the community answered
(33 responses)- A73% (24)
- B3% (1)
- C15% (5)
- D9% (3)
Explanation
A high volume of DNS queries to unknown domains may indicate domain generation algorithm (DGA) activity associated with malware. Checking for data exfiltration is the next logical step to determine if sensitive data is being leaked to these domains. Reconfiguring DNS settings, browsing unknown domains, or blocking the domains are reactive steps that do not address the root cause.
Community Discussion
No community discussion yet for this question.