SPLK-5002 · Question #80
The SOC notices over the course of an investigation there are numerous logs like the following: 14-Apr-2024 20:16:49.083 client 15.111.116.918*18345 UDP: query: reallybad.c2.com IN A response…
The correct answer is D. Excessive DNS Failures. The log shows repeated DNS query failures (SERVFAIL) to a suspicious domain (reallybad.c2.com). The correct detection to create is Excessive DNS Failures, which alerts on abnormal patterns of failed DNS lookups that may indicate command-and-control or malware
Question
The SOC notices over the course of an investigation there are numerous logs like the following:
14-Apr-2024 20:16:49.083 client 15.111.116.918*18345 UDP: query:
reallybad.c2.com IN A response: SERVFAIL +E What detection should be created to alert on this behavior for the future?
Options
- AExcessive Endpoint Failures
- BExcessive Network Failures
- CExcessive Authentication Failures
- DExcessive DNS Failures
How the community answered
(42 responses)- A5% (2)
- B7% (3)
- C14% (6)
- D74% (31)
Explanation
The log shows repeated DNS query failures (SERVFAIL) to a suspicious domain (reallybad.c2.com). The correct detection to create is Excessive DNS Failures, which alerts on abnormal patterns of failed DNS lookups that may indicate command-and-control or malware
Topics
Community Discussion
No community discussion yet for this question.