ANS-C01 exam dumps

ANS-C01 practice question 299 of 513

AWS Certified Advanced Networking - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

ANS-C01 Question 299

Select 3

Your company is hosting a public-facing web application on AWS. You are tasked with ensuring that the DNS records for the domain are protected against spoofing and integrity attacks. You decide to implement DNSSEC for your hosted zone in Amazon Route 53. Which of the following steps are required to successfully enable and configure DNSSEC for your domain in Route 53?

  1. A

    Enable DNSSEC signing in the Route 53 hosted zone.

  2. B

    Create a key-signing key (KSK) in AWS KMS and associate it with your hosted zone.

  3. C

    Update your domain's registrar with the Delegation Signer (DS) record generated by Route 53.

  4. D

    Manually configure DNSSEC validation on each Route 53 record within the hosted zone.

  5. E

    Enable DNSSEC validation on the DNS resolvers querying your domain.

Show answer and explanation

Correct answers: A, B, C

Explanation

To enable DNSSEC in Amazon Route 53, you must enable DNSSEC signing for the hosted zone, create a key-signing key (KSK) in AWS KMS, and update your domain's registrar with the DS record generated by Route 53. These steps ensure that DNSSEC is properly configured to protect the integrity of your DNS records. DNSSEC validation is performed by DNS resolvers, and manual configuration of individual records is not necessary.

  • A. Correct.

    Correct. Enabling DNSSEC signing in the hosted zone is a required step to activate DNSSEC for your domain in Route 53.

  • B. Correct.

    Correct. You must create a key-signing key (KSK) in AWS KMS and associate it with your hosted zone to allow cryptographic signing of your DNS records.

  • C. Correct.

    Correct. After enabling DNSSEC and generating the DS record, you must provide this record to your domain's registrar to establish the chain of trust.

  • D. Incorrect.

    Incorrect. DNSSEC applies to the entire hosted zone, and you do not need to manually configure validation for each DNS record.

  • E. Incorrect.

    Incorrect. DNSSEC validation is performed by the DNS resolvers (e.g., those used by end users), but this step is not required for enabling DNSSEC in Route 53.

Timed practice exam

Take a ANS-C01 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam