ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 119 - AZ-720 discussion

Report
Export

HOTSPOT

A company uses Azure virtual machines (VMs) running Windows for hosting DNS. The company configures the Azure Log Analytics agent on the VMs.

The company is suspicious that some clients may have malware or that the DNS servers may be

compromised. You need to retrieve the following information for troubleshooting:

• Clients that try to resolve malicious domain names.

• Clients that exceed the threshold for the number of DNS lookup requests.

• Changes made to the DNS servers.

You add the DNS Analytics solution to the Azure Log Analytics workspace.

You need to retrieve the required DNS information.

Which query should you use? To answer, select the appropriate options in the answer area.


Question 119
Correct answer: Question 119

Explanation:

Requirement: Clients that resolve malicious domain names.

Query: DNS Security

Explanation: The DNS Security query shows the DNS clients that have attempted to resolve malicious domain names, such as those associated with malware, phishing, or crypto mining. The query also shows the number of malicious queries, the threat type, and the threat level for each client1.


Requirement: Clients that exceed threshold for lookup requests.

Query: DNS Clients

Explanation: The DNS Clients query shows the DNS clients that have sent queries to the DNS servers, along with the number of queries, the average response time, and the percentage of failed queries. The query can be filtered by a threshold value to show only the clients that exceed a certain number of queries2.


Requirement: Changes made to the DNS servers.

Query: Configuration Events

Explanation: The Configuration Events query shows the changes made to the DNS servers, such as adding or deleting zones, records, or forwarders. The query also shows the user who made the change, the time of the change, and the event ID3.



asked 02/10/2024
Salih Igde
39 questions
User
0 comments
Sorted by

Leave a comment first