nerdexam
Cisco

300-415 · Question #134

Which feature allows reachability to an organization's internally hosted application for an active DNS security policy on a device?

The correct answer is A. Local domain bypass. Local domain bypass is the feature that ensures internally hosted applications remain reachable when a DNS security policy is active by preventing internal DNS queries from being redirected to the cloud security service.

Security and Quality of Service

Question

Which feature allows reachability to an organization's internally hosted application for an active DNS security policy on a device?

Exhibit

300-415 question #134 exhibit

Options

  • ALocal domain bypass
  • BDHCP option 6
  • CDNSCrypt configurator
  • Ddata pokey with redirect

How the community answered

(29 responses)
  • A
    93% (27)
  • B
    3% (1)
  • C
    3% (1)

Why each option

Local domain bypass is the feature that ensures internally hosted applications remain reachable when a DNS security policy is active by preventing internal DNS queries from being redirected to the cloud security service.

ALocal domain bypassCorrect

Local domain bypass allows specific internal domains to be resolved by local DNS servers instead of being redirected to the cloud DNS security service (e.g., Cisco Umbrella), ensuring that queries for internally hosted applications or resources are not intercepted, thus maintaining their reachability and proper resolution within the organization's network.

BDHCP option 6

DHCP option 6 is used to provide DNS server IP addresses to clients, but it does not directly manage bypassing an active DNS security policy for internal applications.

CDNSCrypt configurator

DNSCrypt configurator is a tool or feature for encrypting DNS traffic between the client and resolver, which is unrelated to bypassing a security policy for local domains.

Ddata pokey with redirect

'data pokey with redirect' is not a standard or recognized feature in the context of DNS security policies or Cisco SD-WAN.

Concept tested: DNS security local domain bypass

Source: https://www.cisco.com/c/en/us/td/docs/routers/sdwan/configuration/security/ios-xe-17/security-book-xe/m-security.html#concept_x5p_s3v_g2b

Topics

#DNS Security#Policy Bypass#Internal DNS#SD-WAN Security

Community Discussion

No community discussion yet for this question.

Full 300-415 Practice