312-85 Exam QuestionsBrowse all questions from this exam

312-85 Exam - Question 9


Enrage Tech Company hired Enrique, a security analyst, for performing threat intelligence analysis. While performing data collection process, he used a counterintelligence mechanism where a recursive DNS server is employed to perform interserver DNS communication and when a request is generated from any name server to the recursive DNS server, the recursive DNS servers log the responses that are received. Then it replicates the logged data and stores the data in the central database. Using these logs, he analyzed the malicious attempts that took place over DNS infrastructure.

Which of the following cyber counterintelligence (CCI) gathering technique has Enrique used for data collection?

Show Answer
Correct Answer: A

The technique described involves a recursive DNS server logging responses from name server requests and storing this data in a central database for analysis. This method aligns with passive DNS monitoring, which uses such logs to analyze DNS communications for malicious activity. Therefore, data collection through passive DNS monitoring is the correct answer.

Discussion

6 comments
Sign in to comment
pinguin666Option: A
Nov 7, 2022

Method described is PASSIVE DNS monitoring page 335 module 4

jojo2kOption: A
Oct 20, 2022

Passive DNS monitoring is a counterintelligence mechanism where a recursive DNS server is employed to perform inter-server DNS communication. When a request is generated from any name server to the recursive DNS server, the recursive DNS server logs the responses that are received. Then it replicates the logged data and stores the data in the central database.

LordXanderOption: A
Apr 27, 2023

Passive DNS monitoring is a counterintelligence mechanism

BionicBeaverOption: A
Aug 20, 2023

Answer is A As per Module 04 Page 335 of CTIA Courseware

AbdallaAliOption: A
Jun 18, 2024

It is a passive DNS as described in the Book

keloki2020Option: A
Jul 26, 2023

It is Passive DNS Monitoring. "Passive DNS monitoring is a cyber counterintelligence mechanism where a recursive DNS server is employed to perform inter-server DNS communication. "