4.3.2 Ensure DNS Filter logs all DNS queries and responses

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

DNS filter should log all DNS queries and responses.

Rationale:

DNS filter should log all DNS queries and responses (whether if the DNS category is blocked, monitored, or allowed). This enables SOC or security analyst to do further investigations on security incidents especially on threat hunting or incident response activities. Although there are many data sources that can provide DNS query logs (AD or EDR), but this option should be enabled out of best practice and with assumption that no other data sources is available.

Impact:

By default, allowed DNS is not logged. This creates data gap in threat hunting or incident response activities.

Solution

Review DNS Filter Security Profiles and validate that 'Log all DNS queries and responses' is enabled.

Default Value:

Disabled