Study. uk . com
  1. Home
  2. All questions
  3. Question 389

CompTIA Security+ study material · question 389 of 611

How does DNS filtering interrupt an intrusion before any connection is made?

  1. It inspects the TLS certificate presented
  2. It refuses to resolve known malicious domains
  3. It rewrites the destination address
  4. It blocks the TCP handshake to malicious hosts
Show the answer

Answer: B. It refuses to resolve known malicious domains

Without a resolved address the client never dials out, which stops both the lure and much command-and-control traffic.

Challenge yourself on this topic → Study as cards