nerdexam
Splunk

SPLK-5002 · Question #80

The SOC notices over the course of an investigation there are numerous logs like the following: 14-Apr-2024 20:16:49.083 client 15.111.116.918*18345 UDP: query: reallybad.c2.com IN A response…

The correct answer is D. Excessive DNS Failures. The log shows repeated DNS query failures (SERVFAIL) to a suspicious domain (reallybad.c2.com). The correct detection to create is Excessive DNS Failures, which alerts on abnormal patterns of failed DNS lookups that may indicate command-and-control or malware

Custom Content Development

Question

The SOC notices over the course of an investigation there are numerous logs like the following:

14-Apr-2024 20:16:49.083 client 15.111.116.918*18345 UDP: query:

reallybad.c2.com IN A response: SERVFAIL +E What detection should be created to alert on this behavior for the future?

Options

  • AExcessive Endpoint Failures
  • BExcessive Network Failures
  • CExcessive Authentication Failures
  • DExcessive DNS Failures

How the community answered

(42 responses)
  • A
    5% (2)
  • B
    7% (3)
  • C
    14% (6)
  • D
    74% (31)

Explanation

The log shows repeated DNS query failures (SERVFAIL) to a suspicious domain (reallybad.c2.com). The correct detection to create is Excessive DNS Failures, which alerts on abnormal patterns of failed DNS lookups that may indicate command-and-control or malware

Topics

#DNS detection#SERVFAIL#C2 communication#detection creation

Community Discussion

No community discussion yet for this question.

Full SPLK-5002 Practice