Clark is a professional hacker. He created and configured multiple domains pointing to the same host to switch quickly between the domains and avoid detection. Identify the behavior of the adversary in the above scenario.
A. Unspecified proxy activities
CEH book V12 Module 1 P26
Unspecified Proxy Activities : An adversary can create and configure multiple domains pointing to the same host, thus, allowing an adversary to switch quickly between the domains to avoid detection. Security professionals can find unspecified domains by checking the data feeds that are generated by those domains. Using this data feed, the security professionals can also find any malicious files downloaded and the unsolicited communication with the outside network based on the domains.
So...it's B, 90% sure because there's a very similar question for the CTIA certification and it specifies that for Fast-Flux DNS the way you identifty it is by making use of command-line interface.
Very well structured question, but now I can see that there's a lot of domain-crossing between certifications.
So...I misunderstood the question; the way you identify it is indeed Use of CLI. However, if we have to mention what the attacker is doing, then it would be A
Unspecified Proxy Activities An adversary can create and configure multiple domains pointing to the same host, thus, allowing an adversary to switch quickly between the domains to avoid detection. Security professionals can find unspecified domains by checking the data feeds that are generated by those domains. Using this data feed, the security professionals can also find any malicious files downloaded and the unsolicited communication with the outside network based on the domains.
CEH V12 pg 26
D. Use of DNS tunneling
Explanation:
DNS tunneling is a technique used by adversaries to bypass security controls and exfiltrate data from a compromised network. It involves creating DNS queries and responses that encapsulate other types of traffic, such as command and control communications or stolen data.
upvoted 2 times
...
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
jeremy13
Highly Voted 1 year, 7 months agosunce12
Most Recent 5 months agoLordXander
8 months agoLordXander
7 months, 2 weeks agoD15
10 months, 3 weeks agoinsaniunt
10 months, 4 weeks agoinsaniunt
11 months, 1 week agoVidiMidi
1 year agoIPconfig
1 year agonaija4life
1 year, 4 months agovictorfs
1 year, 6 months agosTaTiK
1 year, 6 months agosausageman
1 year, 7 months agoeli117
1 year, 7 months ago