NSE7_SOC_AR-7.6 · Question #6
Refer to the exhibits. What can you conclude from analyzing the data using the threat hunting module?
The correct answer is B. DNS tunneling is being used to extract confidential data from the local network. Based on the exhibits from the Threat Hunting Monitor, here's what the data shows: - Top Application Service: DNS has the highest count (251,406), far exceeding HTTP or other - Event Messages: There are repeated "Connection Failed" messages from source IP 10.0.1.10 to…
Question
Refer to the exhibits. What can you conclude from analyzing the data using the threat hunting module?
Exhibit
Options
- ASpearphishing is being used to elicit sensitive information.
- BDNS tunneling is being used to extract confidential data from the local network.
- CReconnaissance is being used to gather victim identity information from the mail server.
- DFTP is being used as command-and-control (C&C) technique to mine for data.
How the community answered
(26 responses)- A19% (5)
- B62% (16)
- C12% (3)
- D8% (2)
Explanation
Based on the exhibits from the Threat Hunting Monitor, here's what the data shows: - Top Application Service: DNS has the highest count (251,406), far exceeding HTTP or other - Event Messages: There are repeated "Connection Failed" messages from source IP 10.0.1.10 to destination IP 8.8.8.8 at the same timestamp. - Unusual DNS Activity: The extremely high number of DNS requests (compared to other protocols) is a strong indicator of potential DNS tunneling. DNS tunneling is a technique used by attackers to exfiltrate data or communicate with external servers by encoding data within DNS queries and responses. - Connection Failures: Multiple connection failures to 8.8.8.8 (a public DNS server) suggest that attempts to use DNS for non-standard communication (such as tunneling) are being blocked or The pattern of excessive DNS requests, especially in the absence of similarly high HTTP/HTTPS traffic, and repeated connection failures to a DNS server, strongly suggests that DNS tunneling is being attempted to extract data from the local network.
Topics
Community Discussion
No community discussion yet for this question.
