QuestionQ53
Incident Response Techniques
Refer to the exhibit. Which two actions should be performed based on the intelligence information?
Choose two
- A Block network access to all .shop domains
- B Add a SIEM rule to alert on connections to identified domains.
- C Use the DNS server to block hole all .shop requests.
- D Block network access to identified domains.
- E Route traffic from identified domains to block hole.
Community Discussion