Step by Step Explanation: * A high volume of DNS queries to unknown domains may indicate domain generation algorithm (DGA) activity associated with malware. * Checking for data exfiltration is the next logical step to determine if sensitive data is being leaked to these domains. * Reconfiguring DNS settings, browsing unknown domains, or blocking the domains are reactive steps that do not address the root cause. Reference: CASP+ Exam Objectives 3.1 - Analyze indicators of compromise to determine data exfiltration risks.