nerdexam
Cisco

700-270 · Question #63

Which statement is true when describing the current threat landscape?

The correct answer is C. All companies connect to domains that host malicious files or services.. Option C reflects a sobering reality of modern cybersecurity research: studies (including those from Cisco and similar threat intelligence firms) have consistently shown that virtually all organizations - even those with mature security programs - make DNS queries to domains asso

Identifying Customer Business Challenges and Opportunities

Question

Which statement is true when describing the current threat landscape?

Options

  • AThreats can be prevented by not enabling BYOD services
  • BThreats can be prevented using proactive static policies.
  • CAll companies connect to domains that host malicious files or services.
  • DIf a threat is discovered within the first 24 hours, it can be contained.

How the community answered

(43 responses)
  • A
    2% (1)
  • B
    7% (3)
  • C
    86% (37)
  • D
    5% (2)

Explanation

Option C reflects a sobering reality of modern cybersecurity research: studies (including those from Cisco and similar threat intelligence firms) have consistently shown that virtually all organizations - even those with mature security programs - make DNS queries to domains associated with malware, phishing, or command-and-control infrastructure, often without knowing it. This happens through compromised third-party services, malicious ads, phishing links clicked by users, or supply chain issues.

Why the distractors are wrong:

  • A is false because BYOD is just one attack vector; disabling it doesn't eliminate insider threats, unpatched systems, phishing, or supply chain attacks.
  • B is false because static policies are reactive by nature and cannot anticipate novel, zero-day, or polymorphic threats - the landscape requires adaptive, dynamic defenses.
  • D is false because the average dwell time (time an attacker remains undetected) is measured in weeks to months, not hours; 24-hour detection is an aspirational best case, not a guarantee of containment.

Memory tip: Think of option C as the "nobody is clean" principle - in threat intelligence, universal exposure to malicious domains is a foundational assumption, which is why tools like DNS filtering and threat feeds exist. If it were easy to simply avoid bad domains, those tools wouldn't be necessary.

Topics

#Threat landscape#Malicious domains#Modern threats#Attack surface

Community Discussion

No community discussion yet for this question.

Full 700-270 Practice