Which of the following best describes a use case for a DNS sinkhole?
Choose an answer
Tap an option to check your answer.
Correct answer: A DNS sinkhole can be used to capture traffic to known-malicious domains used by attackers..
Why this is the answer
A DNS sinkhole works by providing false DNS resolution for known-malicious domains. When an infected host or malware attempts to contact a command-and-control (C2) server or other malicious infrastructure, the DNS sinkhole intercepts the request and directs it to a controlled, non-routable, or monitored IP address instead of the actual malicious server. This allows security teams to identify infected devices within their network by observing which devices attempt to connect to these sinkholed domains, effectively "capturing" the traffic without allowing the malicious communication to complete. The other options are incorrect because: Attackers do not view sinkholes as valuable for domain structure; sinkholes are a defensive tool. Sinkholes do not redirect employees to malicious sites; they prevent connections to them. While a sinkhole can attract attention, its primary purpose is not to divert attackers from network resources but to detect and contain internal threats.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed