A SOC alert shows multiple servers and workstations beaconing to a newly observed C2 domain. Some affected servers support a customer portal and cannot be isolated. The domain is not used by legitimate applications. Which containment point gives the best balance of coverage and business impact?
Select an answer to reveal the explanation.
Short Explanation
Think of DNS filtering like putting a stop sign on the road to the bad domain: it catches every internal lookup without yanking the whole host off the network. You want the widest containment with the least collateral damage, and that’s why the firewall’s DNS block wins here. The proxy and endpoint options are useful, but they leave gaps or hit systems you can’t afford to touch.
Full Explanation
DNS filtering at the firewall contains a C2 domain by preventing internal resolvers from returning the malicious domain’s address, so any host that uses approved DNS is stopped before a connection is made. It covers servers and workstations centrally, applies to all applications that rely on DNS, and can be scoped to the single domain, which limits disruption to critical services. A web proxy block stops only traffic that is explicitly proxied, so DNS-based, application-bypass, or non-web beaconing can continue. An endpoint EDR block depends on agent coverage, policy propagation, and the agent remaining enforced; it may miss unmanaged or legacy assets and can be defeated if the endpoint is already compromised. Host isolation removes the beaconing systems from the network, which is a stronger response but can interrupt business functions and is not the best balance when a narrower network-level control is available. Exam caveat: choose the containment point that matches the observed channel and the organization’s tolerance for downtime, not simply the most aggressive block. Operational check: confirm the firewall DNS policy logs blocked lookups for the C2 domain and verify a test host receives a sinkhole or NXDOMAIN response before closing the containment step.