PSE-STRATA · Question #162
What are two benefits of the sinkhole Internet Protocol (IP) address that DNS Security sends to the client in place of malicious IP addresses? (Choose two.)
The correct answer is A. The client communicates with it instead of the malicious IP address D. In situations where the internal DNS server is between the client and the firewall, it gives the. When DNS Security intercepts a request for a malicious domain, it returns a sinkhole IP address - an IP controlled by the security infrastructure - rather than the real malicious destination. Option A is correct because the primary purpose of this substitution is exactly that…
Question
What are two benefits of the sinkhole Internet Protocol (IP) address that DNS Security sends to the client in place of malicious IP addresses? (Choose two.)
Options
- AThe client communicates with it instead of the malicious IP address
- BIt represents the remediation server that the client should visit for patching
- CIt will take over as the new DNS resolver for that client and prevent further DNS requests from
- DIn situations where the internal DNS server is between the client and the firewall, it gives the
How the community answered
(43 responses)- A81% (35)
- B7% (3)
- C12% (5)
Explanation
When DNS Security intercepts a request for a malicious domain, it returns a sinkhole IP address - an IP controlled by the security infrastructure - rather than the real malicious destination. Option A is correct because the primary purpose of this substitution is exactly that: the client sends its traffic to the sinkhole instead of the attacker's server, neutralizing the threat. Option D is correct because when an internal DNS resolver sits between the client and the firewall, the firewall normally only sees the DNS server making queries, not the individual infected client; by sending the sinkhole IP back to the client, the client itself initiates a direct connection to that IP, making the client's address visible to the firewall for logging and enforcement.
Option B is wrong because the sinkhole is a traffic redirect mechanism, not a patch management or remediation server - it blocks harm, it does not fix the infected endpoint. Option C is wrong because the sinkhole IP is a destination address for traffic, not a replacement DNS resolver; it has no role in resolving future DNS queries.
Memory tip: Think of a sinkhole as a drain. Traffic falls into it harmlessly (A), and because the client walks to the drain itself, you can see exactly who walked there (D). The sinkhole does not hand out medicine (not B) and does not answer DNS questions (not C).
Topics
Community Discussion
No community discussion yet for this question.