A company enabled DNS Security Extensions (DNSSEC) for a subdomain that is hosted in Amazon Route 53. DNSSEC signing is enabled and a key-signing key (KSK) has been created. Testing shows a broken chain of trust. How should the security engineer resolve this issue?
Choose an answer
Tap an option to check your answer.
Correct answer: Create a Delegation Signer (DS) record in the parent hosted zone..
Why this is the answer
A broken chain of trust in DNSSEC indicates that the parent zone does not have a record linking to the child zone's DNSSEC keys. To establish this trust, a Delegation Signer (DS) record must be created in the parent hosted zone. This DS record contains a hash of the child zone's Key Signing Key (KSK), allowing resolvers to validate the child zone's keys. Replacing the KSK with a ZSK is incorrect because the KSK is specifically designed for signing other keys and establishing the chain of trust with the parent. Deactivating and reactivating the KSK would not resolve the missing DS record in the parent. Creating a DS record in the subdomain's hosted zone is redundant and does not establish the necessary trust link with the parent.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed