QuestionQ50

Threat Hunting Outcomes

Refer to the exhibit.

Question Image

A security engineer uses Wireshark to observe Link-Local Multicast Name Resolution (LLMNR) and NetBIOS Name Service traffic that could spoof a name-resolution source, forcing communication with an adversary-controlled system and enabling an SMB Relay attack. After identifying the traffic as malicious, the security engineer must determine the gaps in threat detection.

Which gap would an analyst identify?

Explanation

LLMNR name-resolution queries use UDP port 5355, and NetBIOS Name Resolution uses UDP port 137. Monitoring these ports provides visibility into the spoofed name-resolution traffic associated with LLMNR/NetBIOS poisoning and potential SMB relay activity.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!