問題文
A firewall team runs a default-deny ruleset and asks what the roaming security module needs so that its DNS queries stay encrypted. What does the documentation state about those queries?
選択肢
- The module sends the queries in the clear to port 53, and relies on the TCP tunnel to the Secure Web Gateway (SWG) for confidentiality and integrity.
- The module encrypts the queries only when the endpoint is off the corporate network (roaming), and it falls back to the clear inside it.
- The module encrypts the queries on port 853 over TCP only, and an administrator has to enable that behavior in the profile before it takes effect.
- The module supports encryption of the queries on port 443 over TCP or UDP, and it turns encryption on by itself once it senses that 443 over UDP is open.