500-651 · Question #12
Which three options ate attack vectors protected by DNS-Layer security? (Choose three.)
The correct answer is C. Web D. E-mail E. Cloud apps. DNS-Layer security (e.g., Cisco Umbrella) intercepts DNS queries before a connection is established, blocking malicious destinations used by web traffic (C), email (D), and cloud apps (E) - all of which rely on DNS resolution to reach external domains, making them natural…
Question
Which three options ate attack vectors protected by DNS-Layer security? (Choose three.)
Options
- AVoicemail
- BBackups
- CWeb
- DE-mail
- ECloud apps
- FVideo Surveil lance
How the community answered
(15 responses)- A7% (1)
- C80% (12)
- F13% (2)
Explanation
DNS-Layer security (e.g., Cisco Umbrella) intercepts DNS queries before a connection is established, blocking malicious destinations used by web traffic (C), email (D), and cloud apps (E) - all of which rely on DNS resolution to reach external domains, making them natural protection points at the DNS layer.
The distractors are wrong for the same core reason: Voicemail (A), Backups (B), and Video Surveillance (F) typically operate over closed/internal networks, PSTN infrastructure, or proprietary protocols that don't depend on public DNS lookups to external domains - so DNS-layer filtering doesn't intercept their traffic paths.
Memory tip: Think "internet-facing = DNS-dependent." If a service needs to resolve a domain name on the public internet to function (browsing the web, sending email, reaching a SaaS cloud app), DNS security can protect it. If the service is internal or uses non-DNS protocols (phone lines, local backup agents, closed-circuit cameras), DNS-layer security has no leverage over it.
Topics
Community Discussion
No community discussion yet for this question.