A SOC analyst sees a workstation making periodic outbound connections to an unknown IP. To confirm the host is resolving suspicious domains rather than just sending traffic, which DNS telemetry condition is most useful?
Select an answer to reveal the explanation.
Short Explanation
Think of DNS logs as the phone book your malware uses: if you see lookups for brand-new, random-looking domains, that's the tell. Port spikes or process alerts may point to a problem, but they don't prove the host resolved a bad name. The trap is confusing network noise with actual resolution evidence.
Full Explanation
DNS telemetry is useful because it shows what names a host attempted to resolve, not merely that traffic left the network. Newly seen, high-entropy domain lookups fit malware behavior: a beaconing implant may generate or use random-looking domains that do not appear in normal enterprise traffic or baseline allowlists. This directly confirms suspicious resolution activity and can trigger further host or network triage. An outbound port 443 spike is network volume evidence; it can accompany many benign services and does not identify the domain being resolved. EDR process creation events with encoded command lines are host-execution evidence, valuable for detecting suspicious execution but separate from DNS resolution. Proxy TLS certificate issuer anomalies reflect encrypted-session inspection issues and may indicate interception or certificate problems, not a DNS lookup. Exam caveat: choose the telemetry source that proves the specific activity asked for, not a correlated alert from another layer. Operational check: pivot from the host IP to DNS query logs, filter for newly observed or high-entropy domains, and compare against baseline and threat-intel feeds.