Correct Answer: At the DNS resolution stage, before the underlying IP connection is made
Explanation: Umbrella enforces policy at DNS resolution, before the IP connection to a malicious destination is ever made, unlike enforcement after TLS handshake, after HTTP download, during TCP teardown, at post-connection payload inspection, or via offline log review.
Correct Answer: At the DNS resolution stage, before the underlying IP connection is made
Explanation: Umbrella enforces policy at DNS resolution, before the IP connection to a malicious destination is ever made, unlike enforcement after TLS handshake, after HTTP download, during TCP teardown, at post-connection payload inspection, or via offline log review.