ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 135 - SY0-701 discussion

Report
Export

A security analyst receives alerts about an internal system sending a large amount of unusual DNS queries to systems on the internet over short periods of time during non-business hours. Which of the following is most likely occurring?

A.
A worm is propagating across the network.
Answers
A.
A worm is propagating across the network.
B.
Data is being exfiltrated.
Answers
B.
Data is being exfiltrated.
C.
A logic bomb is deleting data.
Answers
C.
A logic bomb is deleting data.
D.
Ransomware is encrypting files.
Answers
D.
Ransomware is encrypting files.
Suggested answer: B

Explanation:

Data exfiltration is a technique that attackers use to steal sensitive data from a target system or network by transmitting it through DNS queries and responses. This method is often used in advanced persistent threat (APT) attacks, in which attackers seek to persistently evade detection in the target environment. A large amount of unusual DNS queries to systems on the internet over short periods of time during non-business hours is a strong indicator of data exfiltration. A worm, a logic bomb, and ransomware would not use DNS queries to communicate with their command and control servers or perform their malicious actions.Reference:CompTIA Security+ Study Guide: Exam SY0-701, 9th Edition, page 487;Introduction to DNS Data Exfiltration;Identifying a DNS Exfiltration Attack That Wasn't Real --- This Time

asked 02/10/2024
Yahya Ozer
35 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first