ANS-C01 Question 299
Select 3Your company is hosting a public-facing web application on AWS. You are tasked with ensuring that the DNS records for the domain are protected against spoofing and integrity attacks. You decide to implement DNSSEC for your hosted zone in Amazon Route 53. Which of the following steps are required to successfully enable and configure DNSSEC for your domain in Route 53?
- A
Enable DNSSEC signing in the Route 53 hosted zone.
- B
Create a key-signing key (KSK) in AWS KMS and associate it with your hosted zone.
- C
Update your domain's registrar with the Delegation Signer (DS) record generated by Route 53.
- D
Manually configure DNSSEC validation on each Route 53 record within the hosted zone.
- E
Enable DNSSEC validation on the DNS resolvers querying your domain.
Show answer and explanation
Correct answers: A, B, C
Explanation
To enable DNSSEC in Amazon Route 53, you must enable DNSSEC signing for the hosted zone, create a key-signing key (KSK) in AWS KMS, and update your domain's registrar with the DS record generated by Route 53. These steps ensure that DNSSEC is properly configured to protect the integrity of your DNS records. DNSSEC validation is performed by DNS resolvers, and manual configuration of individual records is not necessary.
- A. Correct.
Correct. Enabling DNSSEC signing in the hosted zone is a required step to activate DNSSEC for your domain in Route 53.
- B. Correct.
Correct. You must create a key-signing key (KSK) in AWS KMS and associate it with your hosted zone to allow cryptographic signing of your DNS records.
- C. Correct.
Correct. After enabling DNSSEC and generating the DS record, you must provide this record to your domain's registrar to establish the chain of trust.
- D. Incorrect.
Incorrect. DNSSEC applies to the entire hosted zone, and you do not need to manually configure validation for each DNS record.
- E. Incorrect.
Incorrect. DNSSEC validation is performed by the DNS resolvers (e.g., those used by end users), but this step is not required for enabling DNSSEC in Route 53.