ANS-C01 exam dumps

ANS-C01 practice question 33 of 513

AWS Certified Advanced Networking - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

ANS-C01 Question 33

Select 3

Your organization is hosting a web application with a domain name example.com. The DNS records for the domain are managed using Amazon Route 53. You are tasked with configuring DNSSEC to improve the security of your domain. Which of the following steps are required to enable DNSSEC for your domain in Route 53?

  1. A

    Enable DNSSEC signing in the hosted zone settings for the example.com domain in Route 53

  2. B

    Generate a key-signing key (KSK) within Route 53 and configure it in the hosted zone

  3. C

    Upload the DS (Delegation Signer) record for the example.com domain to the domain registrar

  4. D

    Create a CNAME record in Route 53 pointing to your DNSSEC public key

  5. E

    Configure a TTL of 60 seconds for all DNS records in the hosted zone

Show answer and explanation

Correct answers: A, B, C

Explanation

DNSSEC improves the security of DNS by enabling authentication of DNS records. In Amazon Route 53, enabling DNSSEC involves enabling signing in the hosted zone, generating a key-signing key (KSK), and uploading the Delegation Signer (DS) record to the domain registrar. These steps ensure that DNS queries can be validated using cryptographic signatures, protecting against attacks such as DNS spoofing or cache poisoning.

  • A. Correct.

    This is correct. Enabling DNSSEC signing in the hosted zone is the first step to configuring DNSSEC for your domain in Route 53.

  • B. Correct.

    This is correct. The key-signing key (KSK) is required to sign the DNS records and secure the zone. Route 53 allows you to generate and manage this key.

  • C. Correct.

    This is correct. After enabling DNSSEC in Route 53, you need to upload the DS (Delegation Signer) record to your domain registrar to complete the DNSSEC setup.

  • D. Incorrect.

    This is incorrect. A CNAME record is not related to DNSSEC configuration or the signing process.

  • E. Incorrect.

    This is incorrect. Configuring a specific TTL is not a requirement for enabling DNSSEC. TTL values can be adjusted independently of DNSSEC.

Timed practice exam

Take a ANS-C01 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam