An administrator enables DNS filtering on the firewall to block users from visiting malicious websites. Which of the following should the administrator also do? (Choose two.)
A.
Disable DoH in users’ internet browsers.
B.
Update NS record to point to DNS filter servers.
A. Disable DoH in users’ internet browsers DNS over HTTPS (DoH) bypasses traditional DNS filtering by encrypting DNS queries. Disabling it ensures that users cannot circumvent the firewall's DNS filtering rules.
D. Block port 53 to servers on the internet Blocking port 53 prevents DNS queries from bypassing the configured DNS filtering solution, ensuring all queries go through the firewall.
Why Not the Other Options?
B: NS records control domain authority and aren't used for DNS filtering.
C: Blocking port 443 is too broad and would disrupt legitimate HTTPS traffic.
E: Disabling TLS v1.3 weakens overall security and doesn't impact DNS filtering.
F: DNSSEC prevents DNS spoofing but doesn't enforce DNS filtering.
A. Disable DoH in users’ internet browsers.
DoH (DNS over HTTPS) encrypts DNS queries, making them harder for firewalls to filter. If DoH is enabled, users can bypass the firewall's DNS filtering. Therefore, disabling DoH is essential for the firewall to effectively block malicious websites.
B. Update NS record to point to DNS filter servers.
NS (Name Server) records specify the DNS servers responsible for a domain. By updating NS records to point to the DNS filter servers, the firewall can intercept and filter DNS queries before they reach external DNS servers.
This section is not available anymore. Please use the main Exam Page.N10-009 Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Hundo_954
1 week, 1 day agonoone21
3 weeks, 4 days agofc040c7
3 weeks, 6 days agofc040c7
3 weeks, 6 days ago