QuestionQ53

Incident Response Techniques

Question Image

Refer to the exhibit. Which two actions should be performed based on the intelligence information?

Choose two
  • A Block network access to all .shop domains
  • B Add a SIEM rule to alert on connections to identified domains.
  • C Use the DNS server to block hole all .shop requests.
  • D Block network access to identified domains.
  • E Route traffic from identified domains to block hole.
Explanation

The indicators provide specific malicious FQDNs, so security monitoring should alert on connections to those domains and network controls should block access to them. Applying controls to all .shop domains would be unnecessarily broad and could block legitimate services.

Community Discussion

No comments yet. Be the first to start the discussion!