Palo_Alto_Networks
PSE-PLATFORM · Question #191
What happens when the traffic log shows an internal host attempting to open a session to a properly configured sinkhole address?
The correct answer is D. The internal host attempted to use DNS to resolve a known malicious domain into an IP address. You've hit your limit · resets 5am (America/New_York)
Threat Prevention
Question
What happens when the traffic log shows an internal host attempting to open a session to a properly configured sinkhole address?
Options
- AThe internal host tried to resolve a DNS query by connecting to a rogue DNS server.
- BA malicious domain tried to contact an internal DNS server.
- CA rogue DNS server used the sinkhole address to direct traffic to a known malicious domain.
- DThe internal host attempted to use DNS to resolve a known malicious domain into an IP address.
How the community answered
(45 responses)- A18% (8)
- B4% (2)
- C7% (3)
- D71% (32)
Explanation
You've hit your limit · resets 5am (America/New_York)
Topics
#DNS sinkhole#threat prevention#malicious domain#User-ID
Community Discussion
No community discussion yet for this question.