ExamGecko
Question list
Search
Search

Related questions











Question 311 - 200-201 discussion

Report
Export

A network engineer noticed in the NetFlow report that internal hosts are sending many DNS requests to external DNS servers A SOC analyst checked the endpoints and discovered that they are infected and became part of the botnet Endpoints are sending multiple DNS requests but with spoofed IP addresses of valid external sources What kind of attack are infected endpoints involved in1?

A.

DNS hijacking

Answers
A.

DNS hijacking

B.

DNS tunneling

Answers
B.

DNS tunneling

C.

DNS flooding

Answers
C.

DNS flooding

D.

DNS amplification

Answers
D.

DNS amplification

Suggested answer: D

Explanation:

The attack described is a DNS amplification attack. It involves infected endpoints sending DNS requests with spoofed IP addresses to external DNS servers. The DNS servers then send large responses to the spoofed addresses, which are actually the targets of the attack. This can result in a significant amount of traffic being directed at the target, overwhelming their network resources. DNS amplification is a type of Distributed Denial of Service (DDoS) attack that leverages the DNS protocol to amplify the attack traffic.

asked 07/10/2024
Volkan Ozsoy
34 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first