A technician receives the following security alert from the firewall's automated system: Match_Time: 10/10/16 16:20:43 Serial: 002301028176 Device_name: COMPSEC1 Type: CORRELATION Scrusex: domain\samjones Scr: 10.50.50.150 Object_name: beacon detection Object_id: 6005 Category: compromised-host Severity: medium Evidence: host repeatedly visited a dynamic DNS domain (17 time) After reviewing the alert, which of the following is the BEST analysis?
A. the alert is a false positive because DNS is a normal network function
B. this alert indicates a user was attempting to bypass security measures using dynamic DNS
C. this alert was generated by the SIEM because the user attempted too many invalid login attempts
D. this alert indicates an endpoint may be infected and is potentially contacting a suspect hos