When performing threat hunting against a DNS server, which traffic toward the affected domain is considered a starting point?

IT Exam Items Repository › Category: CCNA CyberOps › When performing threat hunting against a DNS server, which traffic toward the affected domain is considered a starting point?