A security analyst receives alerts about an internal system sending a large amount of unusual DNS queries to systems on the internet over short periods of time during non-business hours. Which of the following is most likely occurring?
Choose an answer
Tap an option to check your answer.
Correct answer: Data is being exfiltrated..
Why this is the answer
The scenario describes unusual DNS queries during non-business hours, indicating covert communication. This pattern is highly suggestive of data exfiltration, where an attacker uses DNS tunneling or other techniques to sneak data out of the network. DNS queries are often allowed through firewalls, making them an attractive exfiltration channel. A worm propagating would likely involve more varied network traffic, not just unusual DNS queries. A logic bomb deleting data wouldn't typically manifest as outbound DNS queries. Ransomware encrypting files would cause immediate operational disruption and likely involve command-and-control traffic, but the primary symptom wouldn't be unusual DNS queries.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed