ANS-C01 exam dumps

ANS-C01 practice question 509 of 513

AWS Certified Advanced Networking - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

ANS-C01 Question 509

Select 2

A company is hosting a critical web application on AWS and uses Amazon Route 53 as their DNS service. To ensure the integrity and authenticity of DNS responses and protect against DNS spoofing attacks, the company has decided to implement DNSSEC. Which of the following steps are required to enable DNSSEC in Amazon Route 53?

  1. A

    Enable DNSSEC signing for the hosted zone in Amazon Route 53.

  2. B

    Generate a cryptographic key pair and import the private key into Amazon Route 53.

  3. C

    Publish the DNSSEC DS (Delegation Signer) record with the domain registrar.

  4. D

    Manually configure DNSSEC validation on all client devices accessing the application.

  5. E

    Use AWS Certificate Manager (ACM) to manage the DNSSEC keys and certificates.

Show answer and explanation

Correct answers: A, C

Explanation

To enable DNSSEC in Amazon Route 53, you must first enable DNSSEC signing for the hosted zone, which ensures that DNS responses are signed to verify their authenticity and integrity. Next, you need to publish the DS (Delegation Signer) record with the domain registrar, which links the parent zone to the signed records in the hosted zone, completing the chain of trust. Route 53 manages cryptographic keys automatically, so importing keys is not required. DNSSEC validation is typically performed by resolvers, and AWS Certificate Manager is unrelated to DNSSEC.

  • A. Correct.

    Correct. Enabling DNSSEC signing for the hosted zone is the first step to securing DNS responses in Amazon Route 53. This ensures that DNS responses will be digitally signed.

  • B. Incorrect.

    Incorrect. While cryptographic keys are part of DNSSEC, Amazon Route 53 automatically manages these keys for you, so there's no need to import a private key.

  • C. Correct.

    Correct. The DS record must be published with the domain registrar to establish the chain of trust for DNSSEC.

  • D. Incorrect.

    Incorrect. DNSSEC validation is typically handled by DNS resolvers (e.g., ISPs or corporate DNS servers), not manually configured on client devices.

  • E. Incorrect.

    Incorrect. AWS Certificate Manager (ACM) is used for managing SSL/TLS certificates, not for managing DNSSEC keys or certificates.

Timed practice exam

Take a ANS-C01 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam