Your SOC must stop users from reaching known malicious domains before a web request is sent, while also allowing inspection and policy enforcement for specific outbound URLs. Which architecture best matches these requirements?
Select an answer to reveal the explanation.
Short Explanation
Think of DNS filtering as stopping a car before it leaves the garage by refusing the address lookup; the forward proxy is the toll booth that can read the destination URL and apply rules. If you swap them, you're trying to inspect HTTP with a phone book and block domains with a web proxy. Match the control to the layer: domain before resolution, URL inside the request.
Full Explanation
DNS filtering operates at the resolver layer, so it can prevent a client from receiving an IP address for a known malicious domain before any TCP connection or HTTP request occurs. A forward proxy sits in the application path for outbound web traffic, receives HTTP/HTTPS requests from internal clients, and can evaluate URLs, methods, user identity, and content policy while logging the request. This makes the correct architecture a domain-level control for early blocking plus a URL-level control for granular outbound web governance. The reversed approach is wrong because DNS filtering does not parse HTTP request bodies or full URLs; it sees domain queries and returns or denies resolution. Likewise, using a forward proxy to block domains is incomplete when the goal is to stop resolution itself, since clients may still resolve the domain or use non-proxy paths. An endpoint firewall placed before DNS resolution cannot reliably inspect URLs because URL content is application-layer payload, and host-based enforcement is not a network egress control for all traffic. Exam caveat: CS0-004 expects you to match the telemetry and enforcement point to the protocol layer, not to confuse domain blocking with URL filtering. Operational check: Confirm that resolver logs show blocked DNS queries for malicious domains and that proxy logs show URL policy hits for outbound HTTP requests.