nerdexam
GIAC

GCFE · Question #14

How can an analyst use 'DNS logs' from Windows event logs to track malicious activity?

The correct answer is A. By identifying unusual patterns of DNS queries, which may suggest phishing or malware. See the full explanation below for the reasoning.

Question

How can an analyst use 'DNS logs' from Windows event logs to track malicious activity?

Options

  • ABy identifying unusual patterns of DNS queries, which may suggest phishing or malware
  • BBy monitoring changes to network configurations.
  • CBy tracking the frequency of application updates.
  • DBy listing all connected USB devices.

How the community answered

(37 responses)
  • A
    76% (28)
  • B
    16% (6)
  • C
    3% (1)
  • D
    5% (2)

Community Discussion

No community discussion yet for this question.

Full GCFE Practice