500-651 · Question #92
Which are three key features of DNS-layer security? (Choose three.)
The correct answer is D. Provides visibility into all Internet activity E. Acts as first level of protection by providing security at DNS layer F. Resolves all DNS request through a single recursive DNS service. DNS-layer security (like Cisco Umbrella) works by intercepting DNS queries before a connection is ever established, making it the first line of defense (E) - it blocks threats at the DNS resolution stage before malicious traffic reaches your network. Because every…
Question
Which are three key features of DNS-layer security? (Choose three.)
Options
- AData Loss Prevention
- BRetrospective Analysis
- CReal-time sandboxing
- DProvides visibility into all Internet activity
- EActs as first level of protection by providing security at DNS layer
- FResolves all DNS request through a single recursive DNS service
How the community answered
(40 responses)- A3% (1)
- B8% (3)
- C5% (2)
- D85% (34)
Explanation
DNS-layer security (like Cisco Umbrella) works by intercepting DNS queries before a connection is ever established, making it the first line of defense (E) - it blocks threats at the DNS resolution stage before malicious traffic reaches your network. Because every internet-bound request starts with a DNS lookup, it inherently provides visibility into all internet activity (D), letting you see what domains every device is trying to reach. It also resolves all DNS requests through a single recursive DNS service (F), centralizing control and enforcement across all users and locations without requiring agents on every device.
The distractors are wrong because: A (DLP) is a data classification/exfiltration control, not a DNS function; B (Retrospective Analysis) is a feature of advanced malware protection tools (like Cisco AMP/Secure Endpoint) that re-examine past file behavior; C (Real-time sandboxing) belongs to secure web gateway or email security products that detonate files in an isolated environment.
Memory tip: Think of DNS security as a bouncer at the door - it checks the guest list (domain reputation) before you even open the door (establish a connection), giving you visibility into who's knocking (D), stopping threats first (E), and using one central checkpoint for everyone (F).
Topics
Community Discussion
No community discussion yet for this question.