N10-009 exam dumps

N10-009 practice question 271 of 329

Network+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

N10-009 Question 271

Single answerMalware

A network administrator notices that several user workstations are making repeated outbound DNS requests to random-looking domain names every few seconds, even when the users are not actively browsing. Shortly afterward, the affected systems begin connecting to unfamiliar external IP addresses over HTTPS. Standard antivirus signatures do not detect any known infection. Which type of malware is the BEST match for this behavior?

  1. A

    Botnet malware using domain generation algorithms (DGA) for command-and-control

  2. B

    Ransomware encrypting local files before demanding payment

  3. C

    Logic bomb triggered by a specific date and time

  4. D

    Fileless malware that only runs in memory and never communicates externally

Show answer and explanation

Correct answer: A

Explanation

The best answer is botnet malware using domain generation algorithms for command-and-control. In real environments, defenders often identify malware not by file signatures alone but by network indicators such as DNS tunneling patterns, beaconing intervals, unusual domain entropy, and outbound encrypted sessions to suspicious destinations. DGAs are a well-documented technique used by malware families to make takedown and blocking more difficult because infected systems can generate large numbers of possible domains and attempt to contact whichever one the attacker has registered. This aligns with network security monitoring guidance from organizations such as CISA, NIST, and major security vendors, which emphasize detecting anomalous DNS behavior and C2 beaconing as key malware indicators. From a Network+ perspective, the scenario tests recognition of practical malware behavior on the network rather than simple definition recall.

  • A. Correct.

    Correct. Botnet malware commonly uses command-and-control (C2) infrastructure to receive instructions. One evasion technique is a domain generation algorithm (DGA), which causes infected hosts to repeatedly query many pseudo-random domain names until one resolves to an attacker-controlled server. The later HTTPS connections to unfamiliar IPs are consistent with encrypted C2 traffic. This pattern is a practical indicator of malware beaconing and botnet activity on a network.

  • B. Incorrect.

    Incorrect. Ransomware is primarily associated with encrypting files, disrupting access to data, and often displaying a ransom note. While some ransomware families do contact external servers, the scenario emphasizes repeated DNS lookups to random domains and outbound beaconing behavior, which is more characteristic of botnet C2 mechanisms than the main operational signs of ransomware.

  • C. Incorrect.

    Incorrect. A logic bomb is malicious code triggered by a specific condition, such as a date, user action, or system event. It is not typically identified by persistent DNS requests to random domain names and regular outbound HTTPS communication. Someone might choose this option because logic bombs can remain hidden, but the network behavior described points much more strongly to active external command-and-control.

  • D. Incorrect.

    Incorrect. Fileless malware can reside in memory and evade traditional signature-based antivirus, which makes this distractor plausible. However, the statement that it 'never communicates externally' is not accurate as a defining trait. Fileless malware may still beacon to C2 systems. The strongest clue in the scenario is the DGA-like DNS activity and subsequent HTTPS connections, which specifically aligns better with botnet malware using external control channels.

Timed practice exam

Take a N10-009 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam