exam questions

Exam N10-009 All Questions

View all questions & answers for the N10-009 exam

Exam N10-009 topic 1 question 227 discussion

Actual exam question from CompTIA's N10-009
Question #: 227
Topic #: 1
[All N10-009 Questions]

An administrator enables DNS filtering on the firewall to block users from visiting malicious websites. Which of the following should the administrator also do? (Choose two.)

  • A. Disable DoH in users’ internet browsers.
  • B. Update NS record to point to DNS filter servers.
  • C. Block port 443 to the malicious websites.
  • D. Block port 53 to servers on the internet.
  • E. Disable TLS v1.3 in users’ internet browsers.
  • F. Implement DNSSEC for corporate records.
Show Suggested Answer Hide Answer
Suggested Answer: AF 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Hundo_954
1 week, 1 day ago
Selected Answer: AD
A. Disable DoH in users’ internet browsers DNS over HTTPS (DoH) bypasses traditional DNS filtering by encrypting DNS queries. Disabling it ensures that users cannot circumvent the firewall's DNS filtering rules. D. Block port 53 to servers on the internet Blocking port 53 prevents DNS queries from bypassing the configured DNS filtering solution, ensuring all queries go through the firewall. Why Not the Other Options? B: NS records control domain authority and aren't used for DNS filtering. C: Blocking port 443 is too broad and would disrupt legitimate HTTPS traffic. E: Disabling TLS v1.3 weakens overall security and doesn't impact DNS filtering. F: DNSSEC prevents DNS spoofing but doesn't enforce DNS filtering.
upvoted 1 times
...
noone21
3 weeks, 4 days ago
Selected Answer: AB
A. Disable DoH in users’ internet browsers. DoH (DNS over HTTPS) encrypts DNS queries, making them harder for firewalls to filter. If DoH is enabled, users can bypass the firewall's DNS filtering. Therefore, disabling DoH is essential for the firewall to effectively block malicious websites. B. Update NS record to point to DNS filter servers. NS (Name Server) records specify the DNS servers responsible for a domain. By updating NS records to point to the DNS filter servers, the firewall can intercept and filter DNS queries before they reach external DNS servers.
upvoted 1 times
...
fc040c7
3 weeks, 6 days ago
Selected Answer: BF
All the other answers should not be blocked or disabled. 143 - HTTPS important, 53 - DNS IMPORTANT, TLS v1.3 come on now
upvoted 1 times
fc040c7
3 weeks, 6 days ago
Doh, DNS over HTTPS btw
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago