ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 296 - SCS-C02 discussion

Report
Export

A company needs to implement DNS Security Extensions (DNSSEC) for a specific subdomain. The subdomain is already registered with Amazon Route 53. A security engineer has enabled DNSSEC signing and has created a key-signing key (KSK). When the security engineer tries to test the configuration, the security engineer receives an error for a broken trust chain.

What should the security engineer do to resolve this error?

A.
Replace the KSK with a zone-signing key (ZSK).
Answers
A.
Replace the KSK with a zone-signing key (ZSK).
B.
Deactivate and then activate the KSK.
Answers
B.
Deactivate and then activate the KSK.
C.
Create a Delegation Signer (DS) record in the parent hosted zone.
Answers
C.
Create a Delegation Signer (DS) record in the parent hosted zone.
D.
Create a Delegation Signer (DS) record in the subdomain.
Answers
D.
Create a Delegation Signer (DS) record in the subdomain.
Suggested answer: C
asked 16/09/2024
Eric Tegels
44 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first