Correct Answer: Centrally managed DNS security policy enforced consistently for on-network and roaming users, regularly updated threat intelligence, a defined process for handling miscategorized domains, and periodic review of blocked/allowed category lists against business needs
Explanation: Centrally managed, consistently enforced policy, current threat intelligence, a miscategorization process, and periodic category review together provide mature DNS security governance, unlike a static one-time policy, protecting only on-network devices, stale threat intelligence, no miscategorization process, or unreviewed policy changes by any employee.
Correct Answer: Centrally managed DNS security policy enforced consistently for on-network and roaming users, regularly updated threat intelligence, a defined process for handling miscategorized domains, and periodic review of blocked/allowed category lists against business needs
Explanation: Centrally managed, consistently enforced policy, current threat intelligence, a miscategorization process, and periodic category review together provide mature DNS security governance, unlike a static one-time policy, protecting only on-network devices, stale threat intelligence, no miscategorization process, or unreviewed policy changes by any employee.