SOA-C03 · Question #123
A company that runs multiple workloads on AWS wants to enhance its security posture by implementing DNS-based threat protection. The company must block DNS-based attacks. Which solution will meet this
The correct answer is C. Configure Amazon Route 53 Resolver to forward DNS queries to Route 53 Resolver DNS. Amazon Route 53 Resolver DNS Firewall provides DNS-based threat protection by allowing you to create rule groups that block queries to known malicious domains and apply domain filtering policies across your VPCs. By configuring the Route 53 Resolver to forward DNS queries through
Question
A company that runs multiple workloads on AWS wants to enhance its security posture by implementing DNS-based threat protection. The company must block DNS-based attacks. Which solution will meet this requirement?
Options
- ADeploy AWS Shield Advanced to filter and block malicious DNS queries. Set up domain filtering
- BUse AWS WAF to inspect DNS traffic for malicious domains. Create custom rules to block known
- CConfigure Amazon Route 53 Resolver to forward DNS queries to Route 53 Resolver DNS
- DConfigure AWS Config to monitor DNS queries and DNS traffic patterns. Use an AWS Lambda
How the community answered
(24 responses)- A17% (4)
- B4% (1)
- C75% (18)
- D4% (1)
Explanation
Amazon Route 53 Resolver DNS Firewall provides DNS-based threat protection by allowing you to create rule groups that block queries to known malicious domains and apply domain filtering policies across your VPCs. By configuring the Route 53 Resolver to forward DNS queries through the DNS Firewall, you ensure that all DNS traffic is inspected and filtered, effectively blocking DNS-based attacks and malicious domains while keeping DNS resolution within your AWS
Topics
Community Discussion
No community discussion yet for this question.