A company will host a secure web application across multiple EC2 instances and has a Route 53 hosted zone for the application's domain. The company wants to protect the domain from DNS cache-poisoning and allow browsers to authenticate to the application using a trusted third party. Which combination of actions meets these goals?
Choose an answer
Tap an option to check your answer.
Correct answer: Configure the Route 53 hosted zone to use DNS Security Extensions (DNSSEC). Install X.509 certificates that are signed by a public certificate authority on the EC2 instances..
Why this is the answer
DNSSEC protects against DNS cache-poisoning by digitally signing DNS records, ensuring their authenticity and integrity. Installing X.509 certificates signed by a public certificate authority (CA) allows browsers to authenticate the application as trusted, as the CA verifies the identity of the certificate owner. Self-signed certificates are not trusted by browsers by default and would lead to security warnings. NAPTR records are used for DNS-based ENUM (E.164 Number Mapping) and are not relevant for protecting against cache-poisoning or browser authentication.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed