ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 512 - SY0-601 discussion

Report
Export

A security analyst receives alerts about an internal system sending a large amount of unusual DNS queries to systems on the internet over short periods of time during non-business hours. Which of the following is most likely occurring?

A.
A worm is propagating across the network.
Answers
A.
A worm is propagating across the network.
B.
Data is being exfiltrated.
Answers
B.
Data is being exfiltrated.
C.
A logic bomb is deleting data.
Answers
C.
A logic bomb is deleting data.
D.
Ransomware is encrypting files.
Answers
D.
Ransomware is encrypting files.
Suggested answer: B

Explanation:

Data is being exfiltrated when an internal system is sending a large amount of unusual DNS queries to systems on the internet over short periods of time during non-business hours. Data exfiltration is the unauthorized transfer of data from a system or network to an external destination or actor. Data exfiltration can be performed by malicious insiders or external attackers who have compromised the system or network. DNS queries are requests for resolving domain names to IP addresses. DNS queries can be used as a covert channel for data exfiltration by encoding data in the domain names or subdomains and sending them to a malicious DNS server that can decode and collect the data.

Reference: https://www.comptia.org/blog/what-is-data-exfiltration

https://www.certblaster.com/wp-content/uploads/2020/11/CompTIA-Security-SY0-601-Exam-Objectives-1.0.pdf

asked 02/10/2024
Michael Grisonichi
39 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first