Practice Test Geeks home

CCP SOC Operations & Alert Triage 2

An analyst receives an alert for a high volume of DNS queries to a single external domain from one internal host.
What is the MOST likely threat to investigate first?

Select your answer