ANS-C01 exam dumps

ANS-C01 practice question 35 of 513

AWS Certified Advanced Networking - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

ANS-C01 Question 35

Single answer

Your company is hosting a multi-region application in AWS that needs to provide low-latency DNS resolution for users worldwide. You are using Amazon Route 53 as your DNS service. Compliance requirements mandate the use of DNSSEC to ensure the authenticity of DNS responses. How should you configure DNSSEC in Amazon Route 53 to meet this requirement?

  1. A

    Enable DNSSEC signing on the Route 53 hosted zone and configure a trust anchor with your domain registrar.

  2. B

    Enable DNSSEC validation on the Route 53 hosted zone and configure DNSSEC signing with your domain registrar.

  3. C

    Deploy AWS Certificate Manager (ACM) for DNSSEC signing and validation in Route 53.

  4. D

    Activate Route 53 Resolver DNSSEC validation and configure DNSSEC signing on the hosted zone.

Show answer and explanation

Correct answer: A

Explanation

To meet DNSSEC compliance using Amazon Route 53, you must enable DNSSEC signing on the hosted zone and configure the appropriate trust anchor with the domain registrar. This ensures that DNS responses for your domain are cryptographically signed and can be validated by resolvers for authenticity. Route 53 does not perform DNSSEC validation on hosted zones, and AWS Certificate Manager is not relevant to DNSSEC.

  • A. Correct.

    This is correct. To comply with DNSSEC requirements, you must enable DNSSEC signing on the Route 53 hosted zone and configure a trust anchor with your domain registrar. This ensures DNS responses are authentic and have not been tampered with.

  • B. Incorrect.

    This is incorrect. Route 53 does not support DNSSEC validation on the hosted zone itself. Validation is handled by DNS resolvers, not the authoritative zone.

  • C. Incorrect.

    This is incorrect. AWS Certificate Manager (ACM) is not used for DNSSEC. ACM is used for managing SSL/TLS certificates, not DNSSEC signing or validation.

  • D. Incorrect.

    This is incorrect. Route 53 Resolver DNSSEC validation is used for validating DNSSEC-signed responses as a resolver, not for signing DNS records on hosted zones.

Timed practice exam

Take a ANS-C01 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam