ANS-C01 Question 301
Select 2Your organization is hosting a web application on AWS and uses Amazon Route 53 for DNS. To enhance the security of your DNS records and prevent DNS spoofing, your team has decided to implement DNSSEC. What steps must you take to enable DNSSEC on an Amazon Route 53 hosted zone?
- A
Enable DNSSEC signing on the hosted zone in Amazon Route 53
- B
Export the DS (Delegation Signer) record from the hosted zone and add it to the parent domain registrar
- C
Configure Route 53 Resolver to validate DNSSEC-signed records
- D
Enable DNSSEC on Route 53 Resolver endpoints
- E
Manually sign your DNS records using a third-party DNS tool and upload the signed records to the hosted zone
Show answer and explanation
Correct answers: A, B
Explanation
To secure your DNS records with DNSSEC in Amazon Route 53, you must enable DNSSEC signing on the hosted zone and export the DS record to the parent domain registrar to establish the chain of trust. This ensures that DNS resolvers can verify the authenticity of your DNS data. The other options are either unrelated to hosted zone DNSSEC or incorrect for this scenario.
- A. Correct.
Correct. Enabling DNSSEC signing on the hosted zone is the first step to activate DNSSEC for a Route 53 hosted zone. This step ensures that Route 53 generates and manages the necessary DNSSEC keys.
- B. Correct.
Correct. After enabling DNSSEC signing, you must export the DS record and provide it to the parent domain registrar. This is required for the chain of trust to be established between the parent domain and your hosted zone.
- C. Incorrect.
Incorrect. DNSSEC validation is not configured directly within Route 53 Resolver for this use case. Instead, this is typically handled by the resolver's clients or other DNS resolvers.
- D. Incorrect.
Incorrect. While Route 53 Resolver endpoints can perform DNSSEC validation for incoming queries, enabling DNSSEC on the hosted zone is unrelated to this configuration.
- E. Incorrect.
Incorrect. DNSSEC signing is automatically managed by Route 53 for hosted zones when DNSSEC signing is enabled. There is no need to manually sign the records.