PCNSA · Question #254
What are the three DNS Security categories available to control DNS traffic? (Choose three.)
The correct answer is A. Parked Domains D. Phishing Domains E. Malware Domains. Parked Domains (A), Phishing Domains (D), and Malware Domains (E) are the three recognized DNS Security categories used by next-generation firewalls (such as Palo Alto Networks) to classify and control DNS traffic at the DNS layer. Parked Domains identifies domains registered…
Question
What are the three DNS Security categories available to control DNS traffic? (Choose three.)
Options
- AParked Domains
- BSpyware Domains
- CVulnerability Domains
- DPhishing Domains
- EMalware Domains
How the community answered
(41 responses)- A90% (37)
- B5% (2)
- C5% (2)
Explanation
Parked Domains (A), Phishing Domains (D), and Malware Domains (E) are the three recognized DNS Security categories used by next-generation firewalls (such as Palo Alto Networks) to classify and control DNS traffic at the DNS layer. Parked Domains identifies domains registered but not actively hosting content (often used for ad fraud or future malicious use), Phishing Domains targets sites designed to steal credentials, and Malware Domains blocks DNS resolution for domains known to distribute or communicate with malware.
Why B and C are wrong: "Spyware" is a threat classification found in Anti-Spyware/Threat Prevention profiles, not a dedicated DNS Security category - spyware-related traffic is handled at a different policy layer. "Vulnerability" is also a Threat Prevention concept tied to exploit signatures (IPS), not a DNS traffic classification.
Memory tip: Think "P-P-M" - Parked, Phishing, Malware - the three DNS Security categories all describe how a domain is used or abused, not how the payload behaves (which is where Spyware and Vulnerability live).
Topics
Community Discussion
No community discussion yet for this question.