ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 468 - CAS-004 discussion

Report
Export

A DNS forward lookup zone named complia.org must:

* Ensure the DNS is protected from on-path attacks.

* Ensure zone transfers use mutual authentication and are authenticated and negotiated.

Which of the following should the security architect configure to meet these requirements? (Select two).

A.
Public keys
Answers
A.
Public keys
B.
Conditional forwarders
Answers
B.
Conditional forwarders
C.
Root hints
Answers
C.
Root hints
D.
DNSSEC
Answers
D.
DNSSEC
E.
CNAME records
Answers
E.
CNAME records
F.
SRV records
Answers
F.
SRV records
Suggested answer: A, D

Explanation:

To protect DNS from on-path attacks and ensure that zone transfers are mutually authenticated and secure, the security architect should configure DNSSEC and Public keys. DNSSEC (Domain Name System Security Extensions) provides protection against DNS spoofing by digitally signing DNS data to ensure its integrity. Public keys are crucial for mutual authentication during zone transfers, ensuring that only authorized parties can exchange DNS zone data. Together, these options help meet both the requirements of securing DNS queries and authenticating zone transfers with cryptographic integrity.

CASP+ CAS-004 Exam Objectives: Domain 3.0 -- Enterprise Security Architecture (DNS Security)

CompTIA CASP+ Study Guide: DNSSEC Implementation and Use of Public Keys

asked 02/10/2024
Jaroslaw Mikolajczyk
36 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first