300-415 · Question #134
Which feature allows reachability to an organization's internally hosted application for an active DNS security policy on a device?
The correct answer is A. Local domain bypass. Local domain bypass is the feature that ensures internally hosted applications remain reachable when a DNS security policy is active by preventing internal DNS queries from being redirected to the cloud security service.
Question
Exhibit
Options
- ALocal domain bypass
- BDHCP option 6
- CDNSCrypt configurator
- Ddata pokey with redirect
How the community answered
(29 responses)- A93% (27)
- B3% (1)
- C3% (1)
Why each option
Local domain bypass is the feature that ensures internally hosted applications remain reachable when a DNS security policy is active by preventing internal DNS queries from being redirected to the cloud security service.
Local domain bypass allows specific internal domains to be resolved by local DNS servers instead of being redirected to the cloud DNS security service (e.g., Cisco Umbrella), ensuring that queries for internally hosted applications or resources are not intercepted, thus maintaining their reachability and proper resolution within the organization's network.
DHCP option 6 is used to provide DNS server IP addresses to clients, but it does not directly manage bypassing an active DNS security policy for internal applications.
DNSCrypt configurator is a tool or feature for encrypting DNS traffic between the client and resolver, which is unrelated to bypassing a security policy for local domains.
'data pokey with redirect' is not a standard or recognized feature in the context of DNS security policies or Cisco SD-WAN.
Concept tested: DNS security local domain bypass
Source: https://www.cisco.com/c/en/us/td/docs/routers/sdwan/configuration/security/ios-xe-17/security-book-xe/m-security.html#concept_x5p_s3v_g2b
Topics
Community Discussion
No community discussion yet for this question.
