nerdexam
CrowdStrike

CCFH-202B · Question #75

Your organization's next-gen firewall has detected evidence of DNS beaconing occurring from an internal source. The firewall provides you with the beaconing host's internal (private) IP address. In…

The correct answer is D. Source IP. You've hit your limit · resets 12:50am (America/New_York)

Network-Based Threat Hunting

Question

Your organization's next-gen firewall has detected evidence of DNS beaconing occurring from an internal source. The firewall provides you with the beaconing host's internal (private) IP address. In an IP search, which field would you leverage to identify the hostname based on this indicator?

Options

  • ADestination IP
  • BBulk Host Audit
  • CExternal IP
  • DSource IP

How the community answered

(51 responses)
  • A
    2% (1)
  • B
    12% (6)
  • C
    6% (3)
  • D
    80% (41)

Explanation

You've hit your limit · resets 12:50am (America/New_York)

Topics

#IP Search#DNS beaconing#Source IP#host identification

Community Discussion

No community discussion yet for this question.

Full CCFH-202B Practice