350-701 · Question #601
An organization is using DNS services for their network and want to help improve the security of the DNS infrastructure. Which action accomplishes this task?
The correct answer is D. Configure Cisco Umbrella and use DNSSEC for domain authentication to authoritative servers. To enhance DNS infrastructure security, an organization should configure Cisco Umbrella and leverage DNSSEC to authenticate domain responses from authoritative DNS servers.
Question
An organization is using DNS services for their network and want to help improve the security of the DNS infrastructure. Which action accomplishes this task?
Options
- AUse DNSSEC between the endpoints and Cisco Umbrella DNS servers.
- BModify the Cisco Umbrella configuration to pass queries only to non-DNSSEC capable zones.
- CIntegrate Cisco Umbrella with Cisco CloudLock to ensure that DNSSEC is functional.
- DConfigure Cisco Umbrella and use DNSSEC for domain authentication to authoritative servers.
How the community answered
(46 responses)- A17% (8)
- B9% (4)
- C4% (2)
- D70% (32)
Why each option
To enhance DNS infrastructure security, an organization should configure Cisco Umbrella and leverage DNSSEC to authenticate domain responses from authoritative DNS servers.
DNSSEC is designed to authenticate responses from authoritative DNS servers to recursive resolvers, not typically between endpoints and recursive resolvers like Cisco Umbrella DNS servers.
Passing queries only to non-DNSSEC capable zones would degrade security by intentionally avoiding the integrity checks that DNSSEC provides.
Cisco CloudLock is a Cloud Access Security Broker (CASB) focused on cloud application security and data protection, and its integration with Umbrella does not directly ensure the functionality or implementation of DNSSEC.
DNSSEC (Domain Name System Security Extensions) provides cryptographic authentication of DNS data, ensuring that responses received from authoritative DNS servers are legitimate and untampered. When configured with Cisco Umbrella, DNSSEC enhances the integrity and authenticity of domain name resolution, protecting against DNS spoofing and cache poisoning attacks.
Concept tested: DNSSEC implementation for DNS infrastructure security
Source: https://docs.umbrella.com/umbrella-user-guide/docs/about-dnssec
Topics
Community Discussion
No community discussion yet for this question.