nerdexam
Palo_Alto_Networks

PSE-STRATA · Question #121

DNS sinkholing helps identify infected hosts on the protected network using DNS traffic in situations where the firewall cannot see the infected client's DNS query (that is, the firewall cannot see…

The correct answer is C. Infected hosts can then be easily identified in the traffic logs because any host that attempts to. See the full explanation below for the reasoning.

Question

DNS sinkholing helps identify infected hosts on the protected network using DNS traffic in situations where the firewall cannot see the infected client's DNS query (that is, the firewall cannot see the originator of DNS query) Which of the following Statements is true?

Options

  • ADNS Sinkholing requires the Vulnerability Protection Profile be enabled.
  • BSinkholing malware DNS queries solves this visibilty problem by forging responses to the client
  • CInfected hosts can then be easily identified in the traffic logs because any host that attempts to
  • DDNS Sinkholing requires a license SinkHole license in order to activate.

How the community answered

(23 responses)
  • A
    4% (1)
  • C
    83% (19)
  • D
    13% (3)

Community Discussion

No community discussion yet for this question.

Full PSE-STRATA Practice