A security analyst is reviewing the logs on an organization's DNS server and notices the following unusual snippet: Which of the following attack techniques was most likely used?
Choose an answer
Tap an option to check your answer.
Correct answer: Footprinting the internal network.
Why this is the answer
The log snippet shows numerous DNS queries for internal-looking domains like fshare.int.complia.org. This indicates an attacker is actively trying to discover internal network resources and naming conventions, a classic reconnaissance technique known as footprinting. Footprinting aims to map out an organization's network infrastructure and identify potential targets. Determining the ISP-assigned address space is usually done through public WHOIS lookups, not repeated internal DNS queries. Bypassing DNS sinkholing would involve resolving malicious domains, not querying internal ones. Attempting initial access would involve direct connection attempts or exploiting vulnerabilities, not just DNS queries. Exfiltrating data would typically involve data being sent out of the network, not just queries for internal resources.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed