CCNP Security 300-740 SSCA Practice Test 19

CCNP Security 300-740 SSCA Practice Test 19 (Hard) - Configuring DNS Security

CISCO CCNP Security Exam Logo

1 / 10

Which security approach inspects and enforces policy on DNS queries to block resolution of known malicious or policy-violating domains before a connection is even established?

2 / 10

Which practical security benefit does blocking a malicious domain at the DNS resolution stage provide compared to only inspecting traffic after a connection to that domain has been established?

3 / 10

Which DNS security policy category would be most relevant for an organization wanting to prevent employees from accessing known phishing and malware-hosting domains while still allowing general web browsing?

4 / 10

Which DNS security consideration is important for an organization with remote employees who are not connected to the corporate network via VPN or SSE tunnel at all times?

5 / 10

Which risk would most likely result from an organization relying solely on endpoint antivirus software with no DNS-layer security for protection against command-and-control communication from compromised devices?

6 / 10

Which combination of DNS security practices would provide strong protection for both office-based and remote employees against malicious domain access?

7 / 10

Which factor would most influence how an organization categorizes and configures which domain categories to block versus allow in its DNS security policy?

8 / 10

Which troubleshooting step would be appropriate if an employee reports that a legitimate business-critical domain is being unexpectedly blocked by DNS security policy?

9 / 10

Which statement accurately describes how DNS security fits into a broader, layered secure access strategy alongside SWG, DLP, and CASB?

10 / 10

Which combination of practices would provide a mature, well-governed DNS security deployment for a large organization with both office-based and remote employees?

Your score is

The average score is 0%

0%