🔥 3-day streak
Cisco CCNA Cybersecurity (200-201 CCNACBR)36 / 145
Question 36 of 145

During intrusion analysis of a captured DNS transaction in Wireshark, an analyst inspects the DNS response header and notices the QR bit is set to 1, the ANCOUNT field shows a value of 8, and the RCODE field is 0. The queried hostname is a randomized 40-character subdomain of a suspicious external domain. Based on interpreting these header fields, what does the analyst most reasonably conclude?

Reviewed for accuracy · Report an issueNext question