QuestionQ53
Network Intrusion AnalysisA network engineer observes in a NetFlow report that internal hosts are sending numerous DNS requests to external DNS servers. A SOC analyst examines the endpoints and finds that they are infected and have become part of a botnet. The endpoints are sending multiple DNS requests using spoofed IP addresses belonging to legitimate external sources. In what type of attack are the infected endpoints involved?
Community Discussion