NSE4 · Question #307
Which statements about DNS filter profiles are true? (Choose two.)
The correct answer is C. They can block DNS request to known botnet command and control servers. D. They can redirect blocked requests to a specific portal. DNS filter profiles on FortiGate operate at the DNS protocol layer, inspecting DNS queries and responses. They can block DNS requests to known botnet command-and-control (C&C) server domains using FortiGuard's botnet domain database (C is correct). They can also redirect…
Question
Which statements about DNS filter profiles are true? (Choose two.)
Options
- AThey can inspect HTTP traffic.
- BThey must be applied in firewall policies with SSL inspection enabled.
- CThey can block DNS request to known botnet command and control servers.
- DThey can redirect blocked requests to a specific portal.
How the community answered
(25 responses)- A4% (1)
- B4% (1)
- C92% (23)
Explanation
DNS filter profiles on FortiGate operate at the DNS protocol layer, inspecting DNS queries and responses. They can block DNS requests to known botnet command-and-control (C&C) server domains using FortiGuard's botnet domain database (C is correct). They can also redirect blocked DNS requests to a customizable block portal/IP instead of simply dropping them (D is correct). DNS filter profiles do not inspect HTTP traffic (A is incorrect) - that is the role of web filtering profiles. DNS filter profiles also do not require SSL inspection (B is incorrect) because standard DNS queries are sent in plaintext over UDP/TCP port 53; SSL inspection is relevant for HTTPS traffic inspection, not DNS.
Topics
Community Discussion
No community discussion yet for this question.