In this video, we cover exercise PCAP_28 from the PCAP badge. We demonstrate how to differentiate legitimate DNS responses from malicious ones using transaction IDs and UDP streams.