When a malware-infected host attempts to resolve a known command-and-control server, the traffic matches a security policy with DNS sinhole enabled, generating a traffic log.
What will be the destination IP Address in that log entry?
If the sinkhole is enabled, the destination IP should be the one specified in the configuration. So, C is the answer. Although, I'd love to know who came up with the term 'sinkhole' - must have been a security professional with a twisted sense of humor.
I agree with Veronika. The traffic matches a security policy with DNS sinkhole enabled, so it makes sense that the destination IP Address would be the sinkhole IP Address.
Hmm, I'm torn between A and C. But I'll go with C since it seems like the most logical choice. Although, with security, you never know what kind of crazy stuff they might pull...
Bettina
6 months agoLawanda
6 months agoMerlyn
6 months agoJeanice
6 months agoKaitlyn
6 months agoDana
6 months agoShelba
6 months agoAshlyn
6 months agoVeronika
6 months agoGenevive
6 months agoLatia
5 months agoRickie
5 months agoHortencia
5 months agoLong
5 months agoLashanda
6 months agoNoelia
6 months ago