CompTIA Security+ SY0-601 – Question281

During a security incident investigation, an analyst consults the company's SIEM and sees an event concerning
high traffic to a known, malicious command-and-control server. The analyst would like to determine the number
of company workstations that may be impacted by this issue. Which of the following can provide this
information?


A.
WAF logs
B. DNS logs
C. System logs
D. Application logs

Correct Answer: B