Soru

Zorluk: OrtaNetwork Security Monitoring and Alerting

A cloud security operations center receives automated alerts flagging unusual outbound DNS query patterns originating from an internal web application server. The telemetry reveals thousands of high-frequency sub-domain requests formatted as encoded payloads appended to an external domain, accompanied by oversized TXT record responses. Which of the following initial actions should the security analyst take to investigate and contain this activity? (Select TWO.)

  1. Isolate the affected application server from the network segment to halt active data exfiltration.Cevap
  2. Inspect DNS resolver query logs and correlate them with endpoint process execution logs to identify the compromised binary.Cevap
  3. C
    Reconfigure perimeter firewall rules to redirect all incoming network traffic intended for the server into a deception honeypot.
  4. D
    Apply an inline network intrusion prevention system (NIPS) rule to perform SSL/TLS decryption on inbound web traffic.

Cevap

The analyst should isolate the affected application server to prevent further data exfiltration and correlate DNS query logs with endpoint process logs to determine the malicious process.
Isolating the affected application server halts covert data transfer across the network, while inspecting DNS query logs alongside host process logs reveals the exact executable performing DNS tunneling.

Adım Adım Çözüm

1
Analyze the network alert indicators.
Identify high-volume sub-domain requests and TXT responses as DNS tunneling for data exfiltration or C2 traffic.
DNS tunneling uses encoded sub-domains to send data outbound and TXT responses to receive data back over standard DNS infrastructure.
2
Execute immediate incident containment.
Isolate the affected host from the network.
Host network segmentation prevents ongoing data exfiltration while preserving system state for analysis.
3
Conduct root-cause analysis via telemetry correlation.
Map network DNS query timestamps to local endpoint process execution logs.
Correlating network telemetry with endpoint execution state identifies the specific process or malware file generating the queries.

Anahtar Kavram

DNS Tunneling Detection and Incident Response Containment
Bu soruyu puanla