nerdexam
Palo_Alto_Networks

PSE-STRATA-PRO-24 · Question #23

What is used to stop a DNS-based threat?

The correct answer is D. DNS sinkholing. DNS-based threats, such as DNS tunneling, phishing, or malware command-and-control (C2) activities, are commonly used by attackers to exfiltrate data or establish malicious communications. Palo Alto Networks firewalls provide several mechanisms to address these threats, and the…

Threat Prevention

Question

What is used to stop a DNS-based threat?

Options

  • ADNS proxy
  • BBuffer overflow protection
  • CDNS tunneling
  • DDNS sinkholing

How the community answered

(35 responses)
  • A
    6% (2)
  • C
    3% (1)
  • D
    91% (32)

Explanation

DNS-based threats, such as DNS tunneling, phishing, or malware command-and-control (C2) activities, are commonly used by attackers to exfiltrate data or establish malicious communications. Palo Alto Networks firewalls provide several mechanisms to address these threats, and the correct method is DNS sinkholing. DNS sinkholing redirects DNS queries for malicious domains to an internal or non-routable IP address, effectively preventing communication with malicious domains. When a user or endpoint tries to connect to a malicious domain, the sinkhole DNS entry ensures the traffic is blocked or routed to a controlled destination. DNS sinkholing is especially effective for blocking malware trying to contact its C2 server or preventing data exfiltration.

Topics

#DNS security#DNS sinkholing#threat prevention#DNS threats

Community Discussion

No community discussion yet for this question.

Full PSE-STRATA-PRO-24 Practice