300-215 Question 167
Single answerAn organization experiences a phishing attack that successfully compromises a user's endpoint. As part of the incident response, the security team utilizes Cisco Umbrella, Cisco Firepower, Cisco Secure Endpoint, and Cisco Secure Network Analytics to investigate and mitigate the threat. Which solution is primarily responsible for identifying malicious domains and blocking DNS requests to them?
- A
Cisco Umbrella
- B
Cisco Firepower
- C
Cisco Secure Endpoint
- D
Cisco Secure Network Analytics
Show answer and explanation
Correct answer: A
Explanation
Cisco Umbrella is specifically designed to provide DNS-layer security by identifying and blocking malicious domains, preventing devices from resolving or connecting to them. This makes it the appropriate solution for the described scenario. While other Cisco solutions contribute to incident response in different ways, they do not focus on DNS-level threat intelligence and protection.
- A. Correct.
Cisco Umbrella provides cloud-delivered threat intelligence and DNS security, which can identify and block malicious domains by preventing DNS requests to those domains.
- B. Incorrect.
Cisco Firepower focuses on intrusion prevention, advanced malware protection, and network traffic analysis, but it does not specialize in blocking DNS requests to malicious domains.
- C. Incorrect.
Cisco Secure Endpoint is designed for endpoint protection, including malware detection and response. While it can detect malicious activity on endpoints, it does not block DNS requests.
- D. Incorrect.
Cisco Secure Network Analytics monitors network traffic for anomalies and threats, but it does not provide DNS-based blocking of malicious domains.