Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

CompTIA CyberSecurity Analyst CySA+ Certification Exam CS0-003 Question # 23 Topic 3 Discussion

CompTIA CyberSecurity Analyst CySA+ Certification Exam CS0-003 Question # 23 Topic 3 Discussion

CS0-003 Exam Topic 3 Question 23 Discussion:
Question #: 23
Topic #: 3

During a routine review of DNS logs, a security analyst observes that Host X has been making frequent DNS requests to domains with random alphanumeric strings, such as ajd8ekthj.xyz. IPS anomaly rules are blocking these domains. This behavior started shortly after a new software installation on the host. Which of the following should the analyst do first to determine whether Host X has been compromised?


A.

Allow the domains because the DNS requests are part of a misconfigured software update.


B.

Check the software installation logs for errors and reinstall the software.


C.

Block all outbound connections from the host to prevent further DNS queries.


D.

Use threat intelligence to check if the queried domains are associated with legitimate sites.


Get Premium CS0-003 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.