16. An administrator implements web-filtering products but still sees that users are visiting malicious links. Which of the following configuration items does the security administrator need to review?
Answer: B
Content categorization needs to be reviewed.
The security administrator should focus on reviewing content categorization, as this aspect directly impacts the effectiveness of web-filtering products in blocking access to malicious links. If content categorization is not properly configured, users may still be able to access harmful websites.
A) Intrusion prevention system
While an intrusion prevention system (IPS) is essential for network security, it primarily focuses on detecting and preventing malicious activity within the network rather than filtering web content. Therefore, it does not directly address the issue of users visiting malicious links.
B) Content categorization
Content categorization is crucial for effective web filtering, as it determines how websites are classified and whether they are blocked or allowed. If the categorization is inaccurate or insufficient, users may still access malicious links despite the implementation of web-filtering products, making this the correct area to review.
C) Encryption
Encryption is related to securing data in transit and at rest, but it does not influence the functionality of web-filtering products. Reviewing encryption settings will not resolve the issue of users accessing malicious links, as it does not pertain to content filtering.
D) DNS service
The DNS service is responsible for resolving domain names to IP addresses, but it does not inherently filter web content. While issues with DNS could lead to misdirected traffic, it is not the primary factor in why users are accessing malicious links if the web-filtering measures are in place.
Conclusion
Content categorization is essential for the effectiveness of web-filtering products, as it determines the classification of web content that users can access. The other options, while important for overall network security, do not address the specific issue of users visiting malicious links as directly as content categorization does. Therefore, reviewing this configuration item is necessary to enhance security measures effectively.