How can these two assist with identifying or reconstructing a compromise or incident?

DNS logging can capture URL resolution requests and responses. How can these two assist with identifying or reconstructing a compromise or incident? (Choose two.)
A. The DNS queries will identify the external server that was being accessed for the incident transactions.
B. The DNS name may exhibit exfiltrated data as the subdomain.
C. The DNS server can resolve local subdomain names and refer to an outside DNS server for external service name resolution.
D. The DNS query translates a URL to an IP address.

cisco-exams

Leave a Reply

Your email address will not be published. Required fields are marked *


The reCAPTCHA verification period has expired. Please reload the page.