ANS-C01 exam dumps

ANS-C01 practice question 512 of 513

AWS Certified Advanced Networking - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

ANS-C01 Question 512

Select 2

Your organization has deployed an application that utilizes Amazon Route 53 for DNS hosting. To ensure the integrity of DNS responses and prevent DNS spoofing attacks, the security team has mandated the use of DNSSEC. Which of the following actions must you take to implement DNSSEC for your public hosted zone in Route 53?

  1. A

    Enable DNSSEC signing for the hosted zone in Route 53.

  2. B

    Create a key-signing key (KSK) in AWS KMS and associate it with the hosted zone.

  3. C

    Publish the DNSSEC DS (Delegation Signer) record in the parent domain's DNS registry.

  4. D

    Enable DNSSEC validation on all Route 53 resolver endpoints.

  5. E

    Configure a private hosted zone to use Route 53 Resolver DNSSEC features.

Show answer and explanation

Correct answers: A, C

Explanation

To implement DNSSEC for a public hosted zone in Route 53, you must enable DNSSEC signing for the hosted zone and publish the DS record in the parent domain's DNS registry. These steps ensure that DNS responses are digitally signed and that resolvers can validate the authenticity of the DNS data. Route 53 simplifies the management of DNSSEC by handling key management internally, and DNSSEC is not applicable to private hosted zones or resolver endpoints.

  • A. Correct.

    Correct. DNSSEC signing must be enabled in Route 53 for the hosted zone to generate digitally signed DNS responses.

  • B. Incorrect.

    Incorrect. Route 53 automatically manages key-signing keys (KSKs) for DNSSEC, so you do not need to create or manage one manually in AWS KMS.

  • C. Correct.

    Correct. The DS record must be published in the parent domain's DNS registry to signal the use of DNSSEC to resolvers.

  • D. Incorrect.

    Incorrect. Enabling DNSSEC validation is a resolver-side setting and is unrelated to configuring DNSSEC for a hosted zone in Route 53.

  • E. Incorrect.

    Incorrect. DNSSEC is supported only for public hosted zones in Route 53, not private hosted zones.

Timed practice exam

Take a ANS-C01 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam