SY0-701 exam dumps

SY0-701 practice question 329 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 329

Single answerDNS filtering

A company recently had several users click links in phishing emails that attempted to send them to newly registered domains hosting credential-harvesting pages. The security team wants a control that can block users from reaching known malicious domains and domains that match risky categories, while requiring minimal changes to user devices. Which solution would best meet this requirement?

  1. A

    Implement DNS filtering through the organization's recursive DNS service and enforce use of that resolver

  2. B

    Deploy full disk encryption on all endpoints to prevent access to phishing websites

  3. C

    Configure NAC to verify endpoint posture before granting network access

  4. D

    Enable load balancing across the web proxy cluster to improve availability

Show answer and explanation

Correct answer: A

Explanation

DNS filtering is designed to stop connections early by controlling how domain name requests are resolved. In this scenario, the company wants to block known malicious domains and risky categories with minimal endpoint impact, which aligns closely with DNS filtering delivered by a recursive resolver or cloud-based protective DNS service. This approach is widely recommended as a layered defense against phishing, command-and-control callbacks, and access to inappropriate or high-risk sites. Best practices include forcing clients to use approved DNS resolvers, blocking outbound DNS to unauthorized servers, monitoring DNS logs for suspicious patterns, and combining DNS filtering with email security, user awareness training, and endpoint protection. This aligns with common guidance from security vendors and public-sector recommendations, including protective DNS concepts described by agencies such as CISA and NIST's broader guidance on layered defensive controls.

  • A. Correct.

    Correct. DNS filtering works by applying security policies at the DNS resolution stage. The organization's recursive DNS resolver, or a secure DNS filtering service, can block requests for known malicious domains, newly observed malicious destinations, or domains in prohibited categories before the user connects to the site. This is practical because it centralizes control and usually requires fewer endpoint changes than installing software on every device, especially if clients are already configured to use corporate DNS or if DNS egress is restricted to approved resolvers.

  • B. Incorrect.

    Incorrect. Full disk encryption protects data at rest if a device is lost or stolen, but it does not prevent a user from resolving or visiting a phishing domain. Someone might choose this option because it is a common endpoint security control, but it addresses a different risk.

  • C. Incorrect.

    Incorrect. Network Access Control can validate device posture, such as patch level or presence of endpoint protection, before allowing devices onto the network. However, NAC does not inherently block access to malicious domains based on DNS lookups. It may be part of a broader security architecture, but it is not the best fit for this requirement.

  • D. Incorrect.

    Incorrect. Load balancing improves performance and availability by distributing traffic across servers or services. It does not provide domain reputation checks, content category blocking, or phishing-domain prevention. This distractor is plausible because web traffic controls may sit in similar network paths, but load balancing is not a DNS security control.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam