350-201 exam dumps

350-201 practice question 117 of 289

Cybersecurity Professional - Performing Cybersecurity Using Cisco Security Technologies. Professional level, Cisco. Free question with the correct answer and a full explanation.

350-201 Question 117

Single answer

Your organization is using Cisco Umbrella to secure cloud-based applications and enforce security policies for employees working remotely. The security team has noticed an increase in DNS requests to malicious domains. Which action should the team prioritize in Cisco Umbrella to mitigate this threat effectively?

  1. A

    Enable DNS-layer security to block requests to known malicious domains.

  2. B

    Configure a firewall policy to block all outbound traffic to the cloud.

  3. C

    Disable access to all cloud applications to prevent potential threats.

  4. D

    Activate Cisco Secure Endpoint for all endpoints to monitor DNS activity.

Show answer and explanation

Correct answer: A

Explanation

Cisco Umbrella's DNS-layer security is designed to block connections to known malicious domains by intercepting and analyzing DNS requests. This proactive approach prevents threats from reaching the network or endpoints, making it the most effective and efficient solution in this scenario. Other options either do not address the DNS-layer threat directly or would negatively impact business operations.

  • A. Correct.

    Enabling DNS-layer security in Cisco Umbrella helps block requests to known malicious domains at the DNS resolution stage, effectively preventing threats before connections are established.

  • B. Incorrect.

    Configuring a firewall policy to block all outbound traffic to the cloud would disrupt legitimate business operations and is not a practical solution.

  • C. Incorrect.

    Disabling access to all cloud applications is overly restrictive and would severely impact productivity without addressing the root cause of the issue.

  • D. Incorrect.

    While Cisco Secure Endpoint monitors endpoint activity, it does not specifically address DNS-layer threats at the network level.

Timed practice exam

Take a 350-201 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam