セキュリティ アナリストは、社内システムが営業時間外の短期間に大量の異常な DNS クエリをインターネット上のシステムに送信しているというアラートを受け取りました。次のうち、最も可能性が高いのはどれですか?
正解:B
Explanation Data is being exfiltrated when an internal system is sending a large amount of unusual DNS queries to systems on the internet over short periods of time during non-business hours. Data exfiltration is the unauthorized transfer of data from a system or network to an external destination or actor. Data exfiltration can be performed by malicious insiders or external attackers who have compromised the system or network. DNS queries are requests for resolving domain names to IP addresses. DNS queries can be used as a covert channel for data exfiltration by encoding data in the domain names or subdomains and sending them to a malicious DNS server that can decode and collect the data. References: https://www.comptia.org/blog/what-is-data-exfiltration https://www.certblaster.com/wp-content/uploads/2020/11/CompTIA-Security-SY0-601-Exam-Objectives-1.0.pd