ANS-C01 exam dumps

ANS-C01 practice question 301 of 513

AWS Certified Advanced Networking - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

ANS-C01 Question 301

Select 2

Your organization is hosting a web application on AWS and uses Amazon Route 53 for DNS. To enhance the security of your DNS records and prevent DNS spoofing, your team has decided to implement DNSSEC. What steps must you take to enable DNSSEC on an Amazon Route 53 hosted zone?

  1. A

    Enable DNSSEC signing on the hosted zone in Amazon Route 53

  2. B

    Export the DS (Delegation Signer) record from the hosted zone and add it to the parent domain registrar

  3. C

    Configure Route 53 Resolver to validate DNSSEC-signed records

  4. D

    Enable DNSSEC on Route 53 Resolver endpoints

  5. E

    Manually sign your DNS records using a third-party DNS tool and upload the signed records to the hosted zone

Show answer and explanation

Correct answers: A, B

Explanation

To secure your DNS records with DNSSEC in Amazon Route 53, you must enable DNSSEC signing on the hosted zone and export the DS record to the parent domain registrar to establish the chain of trust. This ensures that DNS resolvers can verify the authenticity of your DNS data. The other options are either unrelated to hosted zone DNSSEC or incorrect for this scenario.

  • A. Correct.

    Correct. Enabling DNSSEC signing on the hosted zone is the first step to activate DNSSEC for a Route 53 hosted zone. This step ensures that Route 53 generates and manages the necessary DNSSEC keys.

  • B. Correct.

    Correct. After enabling DNSSEC signing, you must export the DS record and provide it to the parent domain registrar. This is required for the chain of trust to be established between the parent domain and your hosted zone.

  • C. Incorrect.

    Incorrect. DNSSEC validation is not configured directly within Route 53 Resolver for this use case. Instead, this is typically handled by the resolver's clients or other DNS resolvers.

  • D. Incorrect.

    Incorrect. While Route 53 Resolver endpoints can perform DNSSEC validation for incoming queries, enabling DNSSEC on the hosted zone is unrelated to this configuration.

  • E. Incorrect.

    Incorrect. DNSSEC signing is automatically managed by Route 53 for hosted zones when DNSSEC signing is enabled. There is no need to manually sign the records.

Timed practice exam

Take a ANS-C01 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam