nerdexam
Cisco

700-765 · Question #93

Which are three key features or benefits of DNS-layer security? (Choose three.)

The correct answer is B. Identify the internet infrastructure used for attacks C. Uncover current & emergent threats D. Protect any device on or off the network. DNS-layer security identifies attack infrastructure, uncovers emerging threats through intelligence correlation, and protects devices regardless of network location.

Cisco Security Solutions

Question

Which are three key features or benefits of DNS-layer security? (Choose three.)

Options

  • AReal-time sandboxing
  • BIdentify the internet infrastructure used for attacks
  • CUncover current & emergent threats
  • DProtect any device on or off the network
  • EData Loss Prevention
  • FRetrospective Analysis

How the community answered

(41 responses)
  • A
    2% (1)
  • B
    85% (35)
  • E
    2% (1)
  • F
    10% (4)

Why each option

DNS-layer security identifies attack infrastructure, uncovers emerging threats through intelligence correlation, and protects devices regardless of network location.

AReal-time sandboxing

Real-time sandboxing is a file detonation capability associated with products like Cisco Secure Malware Analytics, not a DNS-layer security feature.

BIdentify the internet infrastructure used for attacksCorrect

By analyzing DNS query patterns and correlating them with global threat intelligence, Umbrella identifies the domains, IPs, and internet infrastructure that attackers use to stage and execute campaigns.

CUncover current & emergent threatsCorrect

Umbrella continuously correlates DNS activity against threat intelligence feeds to surface both known and newly emerging threats before they cause damage.

DProtect any device on or off the networkCorrect

Because DNS queries are resolved through Umbrella's recursive service regardless of where the device is located, protection applies to any device on-network or roaming off-network without requiring a VPN.

EData Loss Prevention

Data Loss Prevention is not provided by DNS-layer security - it is a separate capability requiring dedicated DLP tooling.

FRetrospective Analysis

Retrospective analysis is a Cisco Secure Endpoint (AMP) capability that re-evaluates file disposition over time, not a function of DNS-layer security.

Concept tested: Cisco Umbrella DNS security benefits and use cases

Source: https://docs.umbrella.com/umbrella-user-guide/docs/dns-protection

Topics

#DNS-layer security#threat identification#device protection#emergent threats

Community Discussion

No community discussion yet for this question.

Full 700-765 Practice