nerdexam
CompTIA

CS0-003 · Question #32

An incident response team receives an alert to start an investigation of an internet outage. The outage is preventing all users in multiple locations from accessing external SaaS resources. The team…

The correct answer is C. DNS. DNS Logs: DDoS attacks often involve overwhelming the DNS infrastructure to disrupt normal internet services. By reviewing DNS logs, the incident response team can identify abnormal traffic patterns, unusual queries, and potential signs of a DDoS attack targeting the…

Submitted by chiamaka_o· Mar 6, 2026Incident Response and Management

Question

An incident response team receives an alert to start an investigation of an internet outage. The outage is preventing all users in multiple locations from accessing external SaaS resources. The team determines the organization was impacted by a DDoS attack. Which of the following logs should the team review first?

Options

  • ACDN
  • BVulnerability scanner
  • CDNS
  • DWeb server

How the community answered

(42 responses)
  • A
    5% (2)
  • B
    14% (6)
  • C
    74% (31)
  • D
    7% (3)

Explanation

DNS Logs: DDoS attacks often involve overwhelming the DNS infrastructure to disrupt normal internet services. By reviewing DNS logs, the incident response team can identify abnormal traffic patterns, unusual queries, and potential signs of a DDoS attack targeting the organization's DNS servers. Analyzing DNS logs can help pinpoint the attack source, the type of attack, and the affected domains.

Topics

#DDoS attack#Incident response#DNS logs#Network troubleshooting

Community Discussion

No community discussion yet for this question.

Full CS0-003 Practice