GIAC
GCFE · Question #14
GCFE Question #14: Real Exam Question with Answer & Explanation
The correct answer is A. By identifying unusual patterns of DNS queries, which may suggest phishing or malware. See the full explanation below for the reasoning.
Question
How can an analyst use 'DNS logs' from Windows event logs to track malicious activity?
Options
- ABy identifying unusual patterns of DNS queries, which may suggest phishing or malware
- BBy monitoring changes to network configurations.
- CBy tracking the frequency of application updates.
- DBy listing all connected USB devices.
Community Discussion
No community discussion yet for this question.