300-415 · Question #423
How does Cisco Umbrella respond to the client if the FQDN in the DNS query is one of the grey-listed domains?
The correct answer is B. It returns the unicast IP addresses of intelligent proxy. If a DNS query's FQDN is grey-listed by Cisco Umbrella, Umbrella responds to the client by returning the unicast IP addresses of its intelligent proxy.
Question
Options
- AIt returns the IP address of the content provider.
- BIt returns the unicast IP addresses of intelligent proxy.
- CIt returns the IP address of the blocked landing page.
- DNo response is sent; traffic is blocked.
How the community answered
(34 responses)- A3% (1)
- B71% (24)
- C18% (6)
- D9% (3)
Why each option
If a DNS query's FQDN is grey-listed by Cisco Umbrella, Umbrella responds to the client by returning the unicast IP addresses of its intelligent proxy.
Returning the IP address of the content provider would bypass Umbrella's inspection for grey-listed domains, which require further scrutiny.
When a domain is grey-listed, Cisco Umbrella doesn't block it outright but instead redirects the client's DNS query to the IP address of its intelligent proxy. The intelligent proxy then performs a deeper inspection of the HTTP/HTTPS traffic in real-time to determine if the content is malicious before allowing or blocking access.
Returning the IP address of a blocked landing page is typically reserved for domains that are definitively identified as malicious or explicitly blocked, not for grey-listed domains requiring inspection.
Not sending a response or blocking traffic outright is for definitively blocked domains, whereas grey-listed domains are subject to conditional access via the intelligent proxy.
Concept tested: Cisco Umbrella Intelligent Proxy behavior for grey-listed domains
Source: https://docs.umbrella.com/umbrella-user-guide/docs/about-the-intelligent-proxy
Topics
Community Discussion
No community discussion yet for this question.