500-651 · Question #18
What are three benefits that Cisco Umbrella brings to DNS-Layer Security? (Choose three.)
The correct answer is B. Blocks Domains/IPs associated with malware, phising, etc C. Delivers cloud based recursive DNS E. Logs all internet activity. Cisco Umbrella operates at the DNS layer, so its core functions are inherently DNS-centric: it blocks malicious domains/IPs (B) before a connection is ever established, delivers cloud-based recursive DNS (C) as its foundational mechanism (all DNS queries route through…
Question
What are three benefits that Cisco Umbrella brings to DNS-Layer Security? (Choose three.)
Options
- AHelps provide breach mitigation
- BBlocks Domains/IPs associated with malware, phising, etc
- CDelivers cloud based recursive DNS
- DProvides profiling of devices
- ELogs all internet activity
- FProvides Sandboxing of malware
How the community answered
(20 responses)- A5% (1)
- B90% (18)
- F5% (1)
Explanation
Cisco Umbrella operates at the DNS layer, so its core functions are inherently DNS-centric: it blocks malicious domains/IPs (B) before a connection is ever established, delivers cloud-based recursive DNS (C) as its foundational mechanism (all DNS queries route through Umbrella's resolvers), and logs all internet activity (E) at the DNS level, giving visibility into every domain lookup across the network.
Why the distractors are wrong:
- A (Breach mitigation) - While Umbrella can reduce breach risk, "breach mitigation" (containing damage after a breach) is not a DNS-layer function it's specifically known for.
- D (Device profiling) - Device profiling is not a DNS-layer security feature; it belongs to NAC (Network Access Control) solutions like Cisco ISE.
- F (Sandboxing) - Sandboxing is a feature of Cisco Threat Grid or advanced malware protection tools, not DNS-layer security.
Memory tip: Think of Umbrella's DNS role with the acronym "BLC" - Block bad domains, Log all queries (E = logs), Cloud DNS resolver. If an answer describes behavior after a connection is made (sandboxing, device profiling), it's not DNS-layer.
Topics
Community Discussion
No community discussion yet for this question.