When a malware-infected host attempts to resolve a known command-and-control server, the traffic matches a security policy with DNS sinhole enabled, generating a traffic log.
What will be the destination IP Address in that log entry?
If the sinkhole is enabled, the destination IP should be the one specified in the configuration. So, C is the answer. Although, I'd love to know who came up with the term 'sinkhole' - must have been a security professional with a twisted sense of humor.
I agree with Veronika. The traffic matches a security policy with DNS sinkhole enabled, so it makes sense that the destination IP Address would be the sinkhole IP Address.
Hmm, I'm torn between A and C. But I'll go with C since it seems like the most logical choice. Although, with security, you never know what kind of crazy stuff they might pull...
Bettina
9 months agoLawanda
9 months agoMerlyn
9 months agoJeanice
9 months agoKaitlyn
9 months agoDana
8 months agoShelba
8 months agoAshlyn
9 months agoVeronika
9 months agoGenevive
9 months agoLatia
8 months agoRickie
8 months agoHortencia
8 months agoLong
8 months agoLashanda
9 months agoNoelia
9 months ago