exam questions

Exam CCFH-202 All Questions

View all questions & answers for the CCFH-202 exam

Exam CCFH-202 topic 1 question 75 discussion

Actual exam question from CrowdStrike's CCFH-202
Question #: 75
Topic #: 1
[All CCFH-202 Questions]

Your organization's next-gen firewall has detected evidence of DNS beaconing occurring from an internal source. The firewall provides you with the beaconing host's internal (private) IP address.

In an IP search, which field would you leverage to identify the hostname based on this indicator?

  • A. Destination IP
  • B. Bulk Host Audit
  • C. External IP
  • D. Source IP
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
NastyNutsu
2 months ago
Selected Answer: D
Source IP: This field represents the IP address from which the network traffic originates. Since you have the internal IP address of the host that is suspected of beaconing, searching based on the Source IP make sense.
upvoted 1 times
...
alanalanalan
7 months, 2 weeks ago
Selected Answer: D
D D. Source IP Source IP host info
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago