When performing threat hunting against a DNS server, which traffic toward the affected domain is considered a starting point?

IT Exam Items RepositoryCategory: CCNA CyberOpsWhen performing threat hunting against a DNS server, which traffic toward the affected domain is considered a starting point?