nerdexam
Cisco

500-651 · Question #12

Which three options ate attack vectors protected by DNS-Layer security? (Choose three.)

The correct answer is C. Web D. E-mail E. Cloud apps. DNS-Layer security (e.g., Cisco Umbrella) intercepts DNS queries before a connection is established, blocking malicious destinations used by web traffic (C), email (D), and cloud apps (E) - all of which rely on DNS resolution to reach external domains, making them natural…

Network Security

Question

Which three options ate attack vectors protected by DNS-Layer security? (Choose three.)

Options

  • AVoicemail
  • BBackups
  • CWeb
  • DE-mail
  • ECloud apps
  • FVideo Surveil lance

How the community answered

(15 responses)
  • A
    7% (1)
  • C
    80% (12)
  • F
    13% (2)

Explanation

DNS-Layer security (e.g., Cisco Umbrella) intercepts DNS queries before a connection is established, blocking malicious destinations used by web traffic (C), email (D), and cloud apps (E) - all of which rely on DNS resolution to reach external domains, making them natural protection points at the DNS layer.

The distractors are wrong for the same core reason: Voicemail (A), Backups (B), and Video Surveillance (F) typically operate over closed/internal networks, PSTN infrastructure, or proprietary protocols that don't depend on public DNS lookups to external domains - so DNS-layer filtering doesn't intercept their traffic paths.

Memory tip: Think "internet-facing = DNS-dependent." If a service needs to resolve a domain name on the public internet to function (browsing the web, sending email, reaching a SaaS cloud app), DNS security can protect it. If the service is internal or uses non-DNS protocols (phone lines, local backup agents, closed-circuit cameras), DNS-layer security has no leverage over it.

Topics

#DNS-Layer security#attack vectors#threat protection#cloud security

Community Discussion

No community discussion yet for this question.

Full 500-651 Practice