The security team enabled DNS Security Extensions (DNSSEC) for the company’s domain in Amazon Route 53 and asks who is responsible for rotating the DNSSEC keys. What explanation should the network engineer give?
Choose an answer
Tap an option to check your answer.
Correct answer: AWS rotates the zone-signing key (ZSK). The company rotates the key-signing key (KSK)..
Why this is the answer
In Amazon Route 53 DNSSEC, AWS automatically rotates the zone-signing key (ZSK) for you. The ZSK is used to sign the records within your hosted zone. However, the key-signing key (KSK), which signs the ZSK and is critical for establishing the chain of trust, is managed and rotated by the customer. This division of responsibility ensures that customers maintain control over the most sensitive key, while AWS handles the more frequent operational task of ZSK rotation. The company rotating both keys is incorrect as AWS manages the ZSK. AWS KMS keys are used for encrypting the KSK, but the question is about DNSSEC key rotation, not KMS key rotation directly. AWS does not rotate the KSK; the customer does.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed