QuestionQ20

Data Collection and Processing

Enrage Tech Company hired Enrique, a security analyst, to perform threat-intelligence analysis. During the data-collection process, he used a counterintelligence mechanism in which a recursive DNS server performs interserver DNS communication. When any name server generates a request to the recursive DNS server, the recursive DNS servers log the received responses. The logged data is then replicated and stored in a central database. Using these logs, he analyzed malicious attempts occurring across the DNS infrastructure.

Which cyber counterintelligence (CCI) gathering technique did Enrique use for data collection?

  • A Data collection through passive DNS monitoring
  • B Data collection through DNS interrogation
  • C Data collection through DNS zone transfer
  • D Data collection through dynamic DNS (DDNS)
Explanation

Passive DNS monitoring collects DNS observations, including queries and responses handled by recursive resolvers, and retains them for retrospective analysis. Logging and centrally storing those observed responses is passive collection; it neither sends investigative DNS queries nor performs zone transfers or dynamic DNS updates.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!