nerdexam
Cisco

700-765 · Question #92

Which are three key features of DNS-layer security? (Choose three.)

The correct answer is D. Provides visibility into all Internet activity E. Acts as first level of protection by providing security at DNS layer F. Resolves all DNS request through a single recursive DNS service. DNS-layer security (Cisco Umbrella) provides full internet activity visibility, serves as the first line of defense at the DNS layer, and routes all DNS requests through a single recursive DNS service.

Cisco Security Solutions

Question

Which are three key features of DNS-layer security? (Choose three.)

Options

  • AData Loss Prevention
  • BRetrospective Analysis
  • CReal-time sandboxing
  • DProvides visibility into all Internet activity
  • EActs as first level of protection by providing security at DNS layer
  • FResolves all DNS request through a single recursive DNS service

How the community answered

(17 responses)
  • A
    6% (1)
  • B
    6% (1)
  • D
    88% (15)

Why each option

DNS-layer security (Cisco Umbrella) provides full internet activity visibility, serves as the first line of defense at the DNS layer, and routes all DNS requests through a single recursive DNS service.

AData Loss Prevention

Data Loss Prevention is not a feature of DNS-layer security - it requires a dedicated DLP product or CASB integration.

BRetrospective Analysis

Retrospective analysis is a capability associated with Cisco Secure Endpoint (AMP), which re-evaluates files after new threat intelligence emerges, not a DNS-layer security feature.

CReal-time sandboxing

Real-time sandboxing is a threat intelligence and file analysis capability, not a function of DNS-layer security.

DProvides visibility into all Internet activityCorrect

Umbrella logs every DNS request across all devices and ports, providing complete visibility into all internet activity including cloud app usage and destination domains.

EActs as first level of protection by providing security at DNS layerCorrect

By intercepting DNS queries before a network connection is established, Umbrella acts as the earliest possible control point, blocking malicious destinations at the DNS layer before any data is exchanged.

FResolves all DNS request through a single recursive DNS serviceCorrect

Umbrella operates its own global recursive DNS infrastructure, routing all DNS requests through this service to enforce security policies and threat blocking for any connected device.

Concept tested: Cisco Umbrella DNS-layer security key features

Source: https://docs.umbrella.com/umbrella-user-guide/docs/what-is-umbrella

Topics

#DNS-layer security#internet visibility#recursive DNS#first line of defense

Community Discussion

No community discussion yet for this question.

Full 700-765 Practice