SSCP Network and Communications Security Practice Question
A small business wants to prevent employees from accessing known malicious websites without deploying a full next-generation firewall. The IT consultant recommends a service that filters DNS queries before they reach the public internet. Which technology is being described?
⚠ Common exam trap
The trap here is assuming that any perimeter security device, such as an IPS or WAF, automatically performs DNS reputation filtering, when those controls inspect different traffic.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A DNS filtering service that blocks resolution of known malicious domains.
DNS filtering works by checking each name resolution request against a threat intelligence feed and returning a block response for known malicious domains. It requires no inline firewall, covers all applications that use DNS, and is simple to deploy for a small business. The other options address different layers or purposes and would not deliver the same lightweight outbound protection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A web application firewall (WAF) placed in front of the company's public website.
Why it's wrong here
A WAF protects a specific web application from attacks such as SQL injection and cross-site scripting by inspecting HTTP traffic to that application. It does not filter outbound DNS queries from employee workstations and does not block access to known malicious domains. It solves a different problem than the one described.
- ✓
A DNS filtering service that blocks resolution of known malicious domains.
Why this is correct
DNS filtering intercepts name resolution requests and refuses to return addresses for domains on a threat intelligence blocklist. Because it operates at the resolution stage, it can prevent connections to malicious sites across all applications without installing a full firewall. This matches the consultant's recommendation and the small business constraint.
- ✗
An intrusion prevention system (IPS) deployed inline at the network perimeter.
Why it's wrong here
An IPS inspects packet payloads and can block exploits, but it is a broader and typically more expensive control than the DNS-based filtering described. It also does not inherently know which domains are malicious unless it maintains its own reputation feeds. The scenario specifically points to filtering DNS queries rather than deep packet inspection.
- ✗
A forward proxy that caches frequently visited web content.
Why it's wrong here
A caching forward proxy improves performance and can log web requests, but caching alone does not block malicious domains. Unless it is configured with URL filtering, it will happily fetch and return content from any site. The described control operates at the DNS layer, not at the HTTP proxy layer.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.