Cisco CCNP Security Core (SCOR) 350-701Content SecurityMedium
A security analyst is investigating a suspected malware infection originating from a user's web browser. The company uses a Cisco Umbrella deployment for DNS-layer security. Upon reviewing the Umbrella logs, the analyst observes that the user attempted to access a domain classified as 'Malware' which was subsequently blocked. What is the primary mechanism by which Cisco Umbrella prevented the malware infection in this scenario?
- ABy inspecting the HTTP payload for malicious code.
- BBy performing deep packet inspection at the network layer.
- CBy blocking the DNS resolution of the malicious domain.
- DBy decrypting and inspecting the SSL/TLS traffic.
Show answer & explanationAnswer & explanation
Correct answer: C. By blocking the DNS resolution of the malicious domain.
Cisco Umbrella operates primarily at the DNS layer. When a user attempts to access a malicious domain, Umbrella intercepts the DNS request and blocks the resolution, preventing the connection to the malicious server from ever being established.
Why the other options are wrong
- A. Umbrella does not typically inspect HTTP payloads; that's a function of a web proxy or NGFW.
- B. Umbrella operates at the DNS layer (application layer for DNS requests), not by performing deep packet inspection at the network layer.
- D. While Umbrella can integrate with web proxies for SSL inspection, its primary prevention mechanism is at the DNS layer, not by decrypting SSL/TLS traffic itself.
DNS-Layer Security (Cisco Umbrella)
A security service that provides protection against malicious domains by intercepting and resolving DNS requests, blocking access to known bad destinations before a connection is established.
- Operates at the DNS layer, providing protection regardless of port or protocol.
- Blocks access to malware, phishing, and C2 servers.
- Can be deployed quickly and provides protection on and off-network.
Memory trick: DNS Request Denied, Danger Dissolved, Defenses Deployed.