nerdexam
Cisco

500-651 · Question #93

Which are three key features or benefits of DNS-layer security? (Choose three.)

The correct answer is B. Identify the internet infrastructure used for attacks C. Uncover current & emergent threats D. Protect any device on or off the network. DNS-layer security (think Cisco Umbrella) works by intercepting DNS queries before a connection is ever established, giving it unique visibility into attacker infrastructure. B is correct because DNS analysis reveals the domains, IPs, and autonomous systems attackers use to…

Network Security

Question

Which are three key features or benefits of DNS-layer security? (Choose three.)

Options

  • AReal-time sandboxing
  • BIdentify the internet infrastructure used for attacks
  • CUncover current & emergent threats
  • DProtect any device on or off the network
  • EData Loss Prevention
  • FRetrospective Analysis

How the community answered

(30 responses)
  • B
    90% (27)
  • E
    3% (1)
  • F
    7% (2)

Explanation

DNS-layer security (think Cisco Umbrella) works by intercepting DNS queries before a connection is ever established, giving it unique visibility into attacker infrastructure. B is correct because DNS analysis reveals the domains, IPs, and autonomous systems attackers use to stage campaigns. C is correct because global DNS query data allows pattern recognition that surfaces new and emerging malicious domains early. D is correct because DNS is used by every internet-connected device regardless of location - routing queries through a secure resolver protects roaming users just as effectively as those on the corporate network.

Why the distractors are wrong:

  • A (Real-time sandboxing) - that's a feature of cloud sandboxing/malware analysis tools (e.g., Cisco Threat Grid), not DNS-layer security.
  • E (Data Loss Prevention) - DLP inspects content for sensitive data; DNS-layer security never sees payload content, only query metadata.
  • F (Retrospective Analysis) - that's a hallmark of endpoint detection tools (e.g., Cisco Secure Endpoint), which trace historical file activity after a threat is identified.

Memory tip: DNS-layer security is "BCD = Block, Catch, Defend everywhere" - it Blocks by identifying attacker infrastructure, Catches emerging threats early, and Defends devices anywhere they connect.

Topics

#DNS Security#Threat Detection#Attack Infrastructure#Network Protection

Community Discussion

No community discussion yet for this question.

Full 500-651 Practice