500-651 · Question #93
Which are three key features or benefits of DNS-layer security? (Choose three.)
The correct answer is B. Identify the internet infrastructure used for attacks C. Uncover current & emergent threats D. Protect any device on or off the network. DNS-layer security (think Cisco Umbrella) works by intercepting DNS queries before a connection is ever established, giving it unique visibility into attacker infrastructure. B is correct because DNS analysis reveals the domains, IPs, and autonomous systems attackers use to…
Question
Which are three key features or benefits of DNS-layer security? (Choose three.)
Options
- AReal-time sandboxing
- BIdentify the internet infrastructure used for attacks
- CUncover current & emergent threats
- DProtect any device on or off the network
- EData Loss Prevention
- FRetrospective Analysis
How the community answered
(30 responses)- B90% (27)
- E3% (1)
- F7% (2)
Explanation
DNS-layer security (think Cisco Umbrella) works by intercepting DNS queries before a connection is ever established, giving it unique visibility into attacker infrastructure. B is correct because DNS analysis reveals the domains, IPs, and autonomous systems attackers use to stage campaigns. C is correct because global DNS query data allows pattern recognition that surfaces new and emerging malicious domains early. D is correct because DNS is used by every internet-connected device regardless of location - routing queries through a secure resolver protects roaming users just as effectively as those on the corporate network.
Why the distractors are wrong:
- A (Real-time sandboxing) - that's a feature of cloud sandboxing/malware analysis tools (e.g., Cisco Threat Grid), not DNS-layer security.
- E (Data Loss Prevention) - DLP inspects content for sensitive data; DNS-layer security never sees payload content, only query metadata.
- F (Retrospective Analysis) - that's a hallmark of endpoint detection tools (e.g., Cisco Secure Endpoint), which trace historical file activity after a threat is identified.
Memory tip: DNS-layer security is "BCD = Block, Catch, Defend everywhere" - it Blocks by identifying attacker infrastructure, Catches emerging threats early, and Defends devices anywhere they connect.
Topics
Community Discussion
No community discussion yet for this question.