Palo_Alto_Networks
PSE-PLATFORM · Question #14
DNS sinkholing helps identify infected hosts on the protected network using DNS traffic in situations where the firewall cannot see the infected client's DNS query (that is, the firewall cannot see…
The correct answer is C. Infected hosts can then be easily identified in the traffic logs because any host that attempts to connect the sinkhole IP address are most likely infected with. Explanation/Reference:
Threat Prevention
Question
DNS sinkholing helps identify infected hosts on the protected network using DNS traffic in situations where the firewall cannot see the infected client's DNS query (that is, the firewall cannot see the originator of DNS query) Which of the following Statements is true?
Options
- ADNS Sinkholing requires the Vulnerability Protection Profile be enabled.
- BSinkholing malware DNS queries solves this visibilty problem by forging responses to the client host queries directed at fake domains created in a controlled
- CInfected hosts can then be easily identified in the traffic logs because any host that attempts to connect the sinkhole IP address are most likely infected with
- DDNS Sinkholing requires a license SinkHole license in order to activate.
How the community answered
(27 responses)- B4% (1)
- C93% (25)
- D4% (1)
Explanation
Explanation/Reference:
Topics
#DNS sinkholing#infected host identification#traffic logs#DNS security
Community Discussion
No community discussion yet for this question.