Courseiva
hardMultiple ChoiceObjective-mapped

350-701 Practice Question: A network administrator is configuring Cisco…

A network administrator is configuring Cisco Umbrella for web security. They want to ensure that all DNS requests from branch offices are sent to Umbrella for policy enforcement, but they have limited control over the branch routers. What is the most effective deployment method?

⚠ Common exam trap

Cisco often tests the misconception that DNS forwarding or proxy configurations on routers are always the best approach, but the trap here is that the question explicitly states 'limited control over branch routers,' making endpoint-based solutions like the roaming client the only viable option for comprehensive DNS security enforcement.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Deploy the Umbrella roaming client on endpoints

The Umbrella roaming client (Option A) is the most effective method because it can be deployed on endpoints to redirect all DNS queries to Umbrella's cloud resolvers, regardless of branch router configuration. This client works at the OS level, intercepting DNS traffic and enforcing policies even when the network path is uncontrolled, making it ideal for scenarios with limited router access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Deploy the Umbrella roaming client on endpoints

    Why this is correct

    Endpoints send DNS directly to Umbrella, no network changes needed.

  • Set up a transparent proxy on the branch routers

    Why it's wrong here

    Proxy configuration is more involved and not DNS-specific.

  • Configure Umbrella as DNS forwarder on the branch routers

    Why it's wrong here

    Requires control over routers, which the administrator does not have.

  • Use PAC files on the clients to redirect web traffic

    Why it's wrong here

    PAC files are for HTTP proxy, not DNS-level enforcement.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

This 350-701 question is part of Courseiva's 978-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-701 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-701 exam.