PSE-STRATA-PRO-24 · Question #23
What is used to stop a DNS-based threat?
The correct answer is D. DNS sinkholing. DNS-based threats, such as DNS tunneling, phishing, or malware command-and-control (C2) activities, are commonly used by attackers to exfiltrate data or establish malicious communications. Palo Alto Networks firewalls provide several mechanisms to address these threats, and the…
Question
What is used to stop a DNS-based threat?
Options
- ADNS proxy
- BBuffer overflow protection
- CDNS tunneling
- DDNS sinkholing
How the community answered
(35 responses)- A6% (2)
- C3% (1)
- D91% (32)
Explanation
DNS-based threats, such as DNS tunneling, phishing, or malware command-and-control (C2) activities, are commonly used by attackers to exfiltrate data or establish malicious communications. Palo Alto Networks firewalls provide several mechanisms to address these threats, and the correct method is DNS sinkholing. DNS sinkholing redirects DNS queries for malicious domains to an internal or non-routable IP address, effectively preventing communication with malicious domains. When a user or endpoint tries to connect to a malicious domain, the sinkhole DNS entry ensures the traffic is blocked or routed to a controlled destination. DNS sinkholing is especially effective for blocking malware trying to contact its C2 server or preventing data exfiltration.
Topics
Community Discussion
No community discussion yet for this question.