You manage an internal AD-integrated zone, corp.contoso.com, hosted on DNS1. Your internal recursive DNS servers (DNS-REC1 and DNS-REC2) must validate responses for this zone even though there is no parent trust chain. You also need to prevent zone enumeration. What two actions should you take?
Choose an answer
Tap an option to check your answer.
Correct answer: Sign corp.contoso.com with DNSSEC using NSEC3 to mitigate zone enumeration., Enable DNSSEC validation on DNS-REC1 and DNS-REC2 and add a trust anchor for corp.contoso.com..
Why this is the answer
To validate responses for an internal AD-integrated zone without a parent trust chain, you must enable DNSSEC validation on the recursive DNS servers (DNS-REC1 and DNS-REC2) and manually add a trust anchor for corp.contoso.com. This allows the recursive servers to verify the digital signatures of DNS records for that specific zone. To prevent zone enumeration, which allows attackers to discover all records within a zone, you should sign corp.contoso.com with DNSSEC using NSEC3. NSEC3 (Next Secure record version 3) hashes the names of records, making it difficult to enumerate them. Publishing a DS record in a public zone is for public DNSSEC delegation, not internal validation. Classic NSEC allows zone enumeration. DoH encrypts DNS queries but doesn't provide DNSSEC validation.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed