List of questions
Related questions
Question 296 - SCS-C02 discussion
A company needs to implement DNS Security Extensions (DNSSEC) for a specific subdomain. The subdomain is already registered with Amazon Route 53. A security engineer has enabled DNSSEC signing and has created a key-signing key (KSK). When the security engineer tries to test the configuration, the security engineer receives an error for a broken trust chain.
What should the security engineer do to resolve this error?
A.
Replace the KSK with a zone-signing key (ZSK).
B.
Deactivate and then activate the KSK.
C.
Create a Delegation Signer (DS) record in the parent hosted zone.
D.
Create a Delegation Signer (DS) record in the subdomain.
Your answer:
0 comments
Sorted by
Leave a comment first