ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 21 - CS0-003 discussion

Report
Export

An incident response team receives an alert to start an investigation of an internet outage. The outage is preventing all users in multiple locations from accessing external SaaS resources. The team determines the organization was impacted by a DDoS attack. Which of the following logs should the team review first?

A.
CDN
Answers
A.
CDN
B.
Vulnerability scanner
Answers
B.
Vulnerability scanner
C.
DNS
Answers
C.
DNS
D.
Web server
Answers
D.
Web server
Suggested answer: C

Explanation:

A distributed denial-of-service (DDoS) attack is a type of cyberattack that aims to overwhelm a target's network or server with a large volume of traffic from multiple sources. A common technique for launching a DDoS attack is to compromise DNS servers, which are responsible for resolving domain names into IP addresses. By flooding DNS servers with malicious requests, attackers can disrupt the normal functioning of the internet and prevent users from accessing external SaaS resources. Official

Reference: https://www.eccouncil.org/cybersecurity-exchange/threat-intelligence/cyber-kill-chain-seven-steps-cyberattack/

asked 02/10/2024
Veronica Puddu
54 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first