When a malware-infected host attempts to resolve a known command-and-control server, the traffic matches a security policy with DNS sinhole enabled, generating a traffic log.
What will be the destination IP Address in that log entry?
If the sinkhole is enabled, the destination IP should be the one specified in the configuration. So, C is the answer. Although, I'd love to know who came up with the term 'sinkhole' - must have been a security professional with a twisted sense of humor.
I agree with Veronika. The traffic matches a security policy with DNS sinkhole enabled, so it makes sense that the destination IP Address would be the sinkhole IP Address.
Hmm, I'm torn between A and C. But I'll go with C since it seems like the most logical choice. Although, with security, you never know what kind of crazy stuff they might pull...
Bettina
7 months agoLawanda
8 months agoMerlyn
8 months agoJeanice
8 months agoKaitlyn
8 months agoDana
7 months agoShelba
7 months agoAshlyn
7 months agoVeronika
8 months agoGenevive
8 months agoLatia
7 months agoRickie
7 months agoHortencia
7 months agoLong
7 months agoLashanda
7 months agoNoelia
8 months ago