Cisco CCNP Security Core (SCOR) 350-701Content SecurityMedium

A security analyst is investigating a suspected malware infection originating from a user's web browser. The company uses a Cisco Umbrella deployment for DNS-layer security. Upon reviewing the Umbrella logs, the analyst observes that the user attempted to access a domain classified as 'Malware' which was subsequently blocked. What is the primary mechanism by which Cisco Umbrella prevented the malware infection in this scenario?

  1. ABy inspecting the HTTP payload for malicious code.
  2. BBy performing deep packet inspection at the network layer.
  3. CBy blocking the DNS resolution of the malicious domain.
  4. DBy decrypting and inspecting the SSL/TLS traffic.
Show answer & explanation

Correct answer: C. By blocking the DNS resolution of the malicious domain.

Cisco Umbrella operates primarily at the DNS layer. When a user attempts to access a malicious domain, Umbrella intercepts the DNS request and blocks the resolution, preventing the connection to the malicious server from ever being established.

Why the other options are wrong

  • A. Umbrella does not typically inspect HTTP payloads; that's a function of a web proxy or NGFW.
  • B. Umbrella operates at the DNS layer (application layer for DNS requests), not by performing deep packet inspection at the network layer.
  • D. While Umbrella can integrate with web proxies for SSL inspection, its primary prevention mechanism is at the DNS layer, not by decrypting SSL/TLS traffic itself.

DNS-Layer Security (Cisco Umbrella)

A security service that provides protection against malicious domains by intercepting and resolving DNS requests, blocking access to known bad destinations before a connection is established.

  • Operates at the DNS layer, providing protection regardless of port or protocol.
  • Blocks access to malware, phishing, and C2 servers.
  • Can be deployed quickly and provides protection on and off-network.

Memory trick: DNS Request Denied, Danger Dissolved, Defenses Deployed.

More Content Security questions