An incident responder is analyzing a compromised corporate workstation and finds evidence of DNS poisoning in the local cache. Which THREE indicators or mitigation strategies are most relevant to identifying and preventing this specific threat? (Choose three)
Trap 1: Abnormally high transaction ID variance within recursive DNS server…
Randomizing transaction IDs is a defense mechanism against cache poisoning rather than an indicator of compromise. Low variance or predictable transaction IDs indicate vulnerable resolver implementations that allow spoofed responses to succeed.क्क
Trap 2: Disabling all outbound UDP traffic on ports other than 53 and 123…
Blocking arbitrary UDP traffic does not stop cache poisoning, because valid DNS queries natively utilize UDP port 53. Restricting outbound ports fails to address the underlying vulnerability of unvalidated response records coming from authoritative servers.क्क
- A
Abnormally high transaction ID variance within recursive DNS server query logs.
Why it fails: Randomizing transaction IDs is a defense mechanism against cache poisoning rather than an indicator of compromise. Low variance or predictable transaction IDs indicate vulnerable resolver implementations that allow spoofed responses to succeed.क्क
- B
Implementation of DNS Security Extensions (DNSSEC) to validate cryptographic signatures.
DNSSEC utilizes digital signatures rooted in the DNS hierarchy to verify the authenticity and integrity of resource records. Enabling DNSSEC prevents attackers from successfully injecting forged DNS responses into resolver caches.क्क
- C
Mismatched transaction IDs and source ports between outgoing queries and incoming responses.
Cache poisoning attacks rely on guessing or brute-forcing transaction IDs and source ports. Identifying anomalies where incoming responses fail to match active query parameters highlights active spoofing attempts against the resolver.क्क
- D
Deployment of encrypted DNS protocols such as DNS over HTTPS (DoH) or TLS (DoT).
Encrypted DNS protocols secure the communication channel between the client and the recursive resolver. This prevents on-path adversaries from observing, intercepting, or altering DNS traffic before it reaches the designated resolver.क्क
- E
Disabling all outbound UDP traffic on ports other than 53 and 123 across gateways.
Why it fails: Blocking arbitrary UDP traffic does not stop cache poisoning, because valid DNS queries natively utilize UDP port 53. Restricting outbound ports fails to address the underlying vulnerability of unvalidated response records coming from authoritative servers.क्क