700-765 · Question #186
Which two attack vectors are protected by DNS-Layer security? (Choose two.)
The correct answer is A. Endpoints B. Email. DNS-layer security blocks malicious domains before a connection is established, protecting endpoints from internet threats and email from phishing and malware delivery via malicious URLs.
Question
Which two attack vectors are protected by DNS-Layer security? (Choose two.)
Options
- AEndpoints
- BEmail
- CCloud
- DControl layer
- EVoiceemail
How the community answered
(26 responses)- A92% (24)
- C4% (1)
- D4% (1)
Why each option
DNS-layer security blocks malicious domains before a connection is established, protecting endpoints from internet threats and email from phishing and malware delivery via malicious URLs.
Endpoints are a primary protected vector because every device must resolve a domain name via DNS before establishing a connection - DNS-layer security intercepts these queries and blocks resolution of known malicious domains before the endpoint can reach the threat.
Email attacks frequently embed malicious URLs that require DNS resolution when clicked by users - DNS-layer security blocks these domains at the resolver level, preventing users from reaching phishing sites or malware distribution points delivered through email campaigns.
Cloud is not a distinct attack vector category in DNS-layer security - cloud-hosted resources are destinations, not a separate protected vector class.
Control layer is not a recognized attack vector in the context of DNS-layer security and does not describe a traffic type that DNS filtering is designed to protect.
Voicemail is not a recognized attack vector protected by DNS-layer security solutions and is not a category covered by platforms such as Cisco Umbrella.
Concept tested: DNS-layer security attack vector protection scope
Source: https://docs.umbrella.com/umbrella-user-guide/docs/what-is-umbrella
Topics
Community Discussion
No community discussion yet for this question.