nerdexam
Fortinet

FCSS_EFW_AD-7.6 · Question #35

An administrator received a FortiAnalyzer alert that a 1 disk filled up in a day. Upon investigation, they found thousands of unusual DNS log requests, such as JHCMQK.website.com, with no answers…

The correct answer is D. Use an IPS profile and DNS exfiltration-related signatures. The excessive DNS log requests with random subdomains suggest a DNS exfiltration attack, where attackers encode and transmit data via DNS queries. Since this technique can use both UDP and TLS (DoH - DNS over HTTPS), a comprehensive security approach is needed. Using an IPS…

Advanced Threat Protection

Question

An administrator received a FortiAnalyzer alert that a 1 disk filled up in a day. Upon investigation, they found thousands of unusual DNS log requests, such as JHCMQK.website.com, with no answers. They later discovered that DNS exfiltration was occurring through both UDP and TLS. How can the administrator prevent this data theft technique?

Options

  • ACreate an inline-CASB to protect against DNS exfiltration.
  • BConfigure a File Filter profile to prevent DNS exfiltration.
  • CEnable DNS Filter to protect against DNS exfiltration.
  • DUse an IPS profile and DNS exfiltration-related signatures.

How the community answered

(34 responses)
  • A
    15% (5)
  • B
    3% (1)
  • C
    9% (3)
  • D
    74% (25)

Explanation

The excessive DNS log requests with random subdomains suggest a DNS exfiltration attack, where attackers encode and transmit data via DNS queries. Since this technique can use both UDP and TLS (DoH - DNS over HTTPS), a comprehensive security approach is needed. Using an IPS profile with DNS exfiltration-specific signatures allows FortiGate to: Detect and block abnormal DNS query patterns often used in exfiltration. Inspect encrypted DNS (DoH, DoT) traffic if SSL inspection is enabled. Identify known exfiltration domains and techniques based on FortiGuard threat intelligence.

Topics

#DNS exfiltration#IPS signatures#DNS over TLS#data exfiltration

Community Discussion

No community discussion yet for this question.

Full FCSS_EFW_AD-7.6 Practice