Palo_Alto_Networks
PSE-STRATA · Question #99
When a malware-infected host attempts to resolve a known command-and-control server, the traffic matches a security policy with DNS sinkhole enabled, generating a traffic log. What will be the…
The correct answer is A. The IP address specified in the sinkhole configuration. See the full explanation below for the reasoning.
Question
When a malware-infected host attempts to resolve a known command-and-control server, the traffic matches a security policy with DNS sinkhole enabled, generating a traffic log. What will be the destination IP address in that log entry?
Options
- AThe IP address specified in the sinkhole configuration.
- BThe IP address of the command-and-control server.
- CThe IP address of sinkhole.paloaltonetworks.com
- DThe IP address of one of the external DNS servers identified in the anti-spyware database.
How the community answered
(41 responses)- A80% (33)
- B2% (1)
- C12% (5)
- D5% (2)
Community Discussion
No community discussion yet for this question.