200-201 Question 252
Single answerYou are monitoring network traffic as part of a cybersecurity operations team. Your intrusion detection system (IDS) flags an alert for suspicious activity involving multiple DNS queries from an internal host. Upon further investigation, you find that the queries are for legitimate, commonly used domains, and there is no evidence of malicious payloads or abnormal behavior. What is the most likely classification for this activity?
- A
Malicious
- B
Benign
- C
Suspicious
- D
Unknown
Show answer and explanation
Correct answer: B
Explanation
In cybersecurity operations, 'benign' activity refers to events or traffic flagged by detection systems that, upon investigation, are determined to be harmless. In this scenario, the flagged DNS queries were found to be legitimate and posed no threat, making 'benign' the correct classification.
- A. Incorrect.
This is incorrect because 'malicious' refers to activity with clear intent to harm, such as malware or an attack. The scenario provides no evidence of malicious intent.
- B. Correct.
This is correct because 'benign' refers to activity that is deemed harmless after investigation, as in this case where the DNS queries are legitimate and show no signs of malicious behavior.
- C. Incorrect.
This is incorrect because 'suspicious' refers to activity that is unusual or requires further monitoring. In this scenario, the investigation has already confirmed the activity is harmless.
- D. Incorrect.
This is incorrect because 'unknown' refers to activity whose intent or nature cannot be determined. Here, the nature of the activity has been identified as harmless.