Lab 22 Flashcards

1
Q

What is the approximate time interval between type 1 queries to badsite.ru?

1 second
5 seconds
20 seconds
1 minute

A

5 seconds

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Which of the following statements are true in regards to the output from the ping command just entered?

The FQDN resolves to a public IP address
No ECHO_REPLIES are received
The domain name resolves to the loopback address
The query operations are being filtered

A

The domain name resolves to the loopback address

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

If there is an abuse or a problem related to the domain name comptia.org, what contact point should be used to report the issue?

armando.ns.cloudflare.com
dns@cloudflare.com
abuse@dns.cloudflare.com
abuse@dns.cloudflare.com

A

dns@cloudflare.com

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Why is beaconing an important IoC to look for?

It indicates active malware attempting to contact a C&C.
It is evidence of buffer overflow exploits.
It is triggered by any malicious activity.
It may use polymorphism to hide its identity.

A

It indicates active malware attempting to contact a C&C.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is the primary limitation of the automation used to block access to malicious FQDNs?

it protects against both the FQDN and the related IP address
it blocks reverse lookups
it allows secure access to the FQDNs of concern
It only protects the individual system where it runs

A

It only protects the individual system where it runs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

In what two modes can nslookup be used? (Select two)

Interactive
Recursive
Automatic
Iterative
Non-interactive

A

Interactive
Non-interactive

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Which option in dig will let you select the DNS record type to return?

-r
-t
-d
-z

A

-t

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is the repeated attempt to resolve a FQDN on a regular interval by unknown software called?

port scanning
DNS spoofing
shell injection
beaconing

A

beaconing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly