200-201 Network Intrusion Analysis • Set 10
200-201 Network Intrusion Analysis Practice Test 10 — 15 questions with explanations. Free, no signup.
A junior analyst is asked to identify which log source would best confirm that an internal workstation attempted to resolve a suspicious domain shortly before an alert fired. The environment forwards DNS query logs from its recursive resolvers to the SIEM. Which action should the analyst take first?
Choose an answer to begin — your selection is scored in the full session.
15 questions · instant feedback and full explanations after every question.