DNS Spoofing & Cache Poisoning Prevention Flashcards

1
Q

Juniper Firewalls can support DNS Security Extensions (DNSSEC), a suite of extensions to DNS that adds an additional layer of security. DNSSEC helps prevent DNS spoofing and cache poisoning by digitally signing DNS records, ensuring their authenticity.

A

DNS Security (DNSSEC)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Juniper Firewalls can inspect DNS traffic for anomalies and malicious domain resolutions. They maintain lists of known malicious domains and can block or alert on DNS requests to such domains.

A

DNS Filtering and Inspection

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

IDS/IPS capabilities in Juniper Firewalls can detect and alert on suspicious DNS traffic patterns associated with cache poisoning attempts. They can identify and block or alert on DNS record manipulation.

A

Intrusion Detection/Prevention System (IDS/IPS)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Juniper Firewalls can use content filtering to restrict access to suspicious or potentially malicious domains. They can block users from accessing websites with a history of DNS spoofing or cache poisoning activities.

A

Content Filtering

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Some Juniper Firewalls use behavior-based analysis to detect abnormal DNS traffic behavior. If DNS requests and responses exhibit characteristics of cache poisoning, the firewall can take action to block or alert.

A

Behavior-Based Analysis

How well did you know this?
1
Not at all
2
3
4
5
Perfectly