While monitoring network traffic, the security analyst observes the following unusual domain access patterns: What is the most likely explanation for these unusual traffic patterns?
Exhibit
| Accessed Domains |
|---|
| abcx.example |
| efgy.example |
| ijkz.example |
| lmnw.example |
| opqv.example |
| rstt.example |
| uvww.example |
| xyzu.example |
Pick an option to open the notes on all of them.
Key and notes on every option
Key: D
- ABGP is the routing protocol between networks on the internet and has nothing to do with clients looking up machine-generated domain names.
- BA remote access trojan might use a DGA to find its controller, but RAT names a type of malware, not the domain pattern shown.
- CMTD is a defensive technology (moving target defense or mobile threat defense), not a pattern of suspicious domain lookups.
- DCorrect: Many lookups of similar, machine-generated names that follow one pattern is the signature of a domain generation algorithm, which malware uses to find its command-and-control server.