ExamGecko
Question list
Search
Search

Related questions











Question 318 - 300-710 discussion

Report
Export

Refer to the Exhibit.

A security engineer must improve security in an organization and is producing a risk mitigation strategy to present to management for approval. Which action must the security engineer take based on this Attacks Risk Report?

A.

Inspect DNS traffic

Answers
A.

Inspect DNS traffic

B.

Block NetBIOS.

Answers
B.

Block NetBIOS.

C.

Block Internal Explorer

Answers
C.

Block Internal Explorer

D.

Inspect TCP port 80 traffic

Answers
D.

Inspect TCP port 80 traffic

Suggested answer: A

Explanation:

Based on the Attacks Risk Report, DNS is associated with a high number of impact events (16). DNS traffic is critical for network operations but can also be exploited for malicious activities such as DNS tunneling, DDoS attacks, and data exfiltration. To improve security, the security engineer should focus on inspecting DNS traffic. This involves deploying DNS security solutions and monitoring DNS traffic for anomalies to detect and mitigate potential threats.

Steps:

Implement DNS security tools such as DNS filtering, DNSSEC, and DNS anomaly detection.

Configure the firewall to inspect DNS traffic for malicious activities.

Regularly analyze DNS logs to identify and respond to threats.

This action addresses a significant risk identified in the report and helps to mitigate potential attacks exploiting DNS.

asked 07/10/2024
abdelhafid houssa
41 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first