Google Professional Cloud Network Engineer Question 541
Single answerGoogle Cloud PlatformYou are managing a Google Cloud project for a financial institution. The institution requires enhanced DNS security for its public domain to ensure DNS responses are authentic and have not been tampered with. How can you enable DNS Security Extensions (DNSSEC) for your public Cloud DNS zone?
- A
Enable DNSSEC in the DNS zone settings and configure DS records at your domain registrar.
- B
Configure a custom DNS resolver in Google Cloud to enable DNSSEC.
- C
Import a pre-signed DNSSEC key into Google Cloud DNS.
- D
Enable DNSSEC in the Cloud DNS settings and no further action is required.
Show answer and explanation
Correct answer: A
Explanation
To enable DNSSEC for a public Cloud DNS zone in Google Cloud, you must first enable DNSSEC in the DNS zone settings in Cloud DNS. This ensures that DNSSEC signing is active for your zone. Additionally, you must configure the Delegation Signer (DS) records at your domain registrar to establish trust between the parent domain and your DNS zone. Without both steps, DNSSEC will not function properly.
- A. Correct.
Correct. Enabling DNSSEC in the DNS zone settings in Cloud DNS and configuring the Delegation Signer (DS) records at your domain registrar are necessary steps to activate DNSSEC for a public domain.
- B. Incorrect.
Incorrect. Configuring a custom DNS resolver does not enable DNSSEC for your public DNS zone. DNSSEC must be enabled directly in the DNS zone settings and DS records must be configured at the domain registrar.
- C. Incorrect.
Incorrect. Cloud DNS manages DNSSEC keys automatically, so importing a pre-signed DNSSEC key is not required.
- D. Incorrect.
Incorrect. While enabling DNSSEC in the Cloud DNS settings is an essential step, you must also configure DS records at your domain registrar to fully enable DNSSEC.