Google Professional Cloud Network Engineer exam dumps

Google Professional Cloud Network Engineer practice question 543 of 790

Professional Cloud Network Engineer. Professional level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Network Engineer Question 543

Select 2Google Cloud Platform

Your company is hosting a production domain on Google Cloud DNS and requires DNSSEC to be enabled for increased security. You have been tasked with setting up DNSSEC for the domain. Which of the following steps are required to successfully enable DNSSEC on your Cloud DNS managed zone?

  1. A

    Enable DNSSEC signing on the managed zone in Google Cloud DNS.

  2. B

    Update the domain's registrar with the DS (Delegation Signer) records from the managed zone.

  3. C

    Create a custom DNS key and manually import it into the managed zone.

  4. D

    Verify that the TTL values for the DNS records match the default DNSSEC requirements.

  5. E

    Disable DNSSEC validation on client resolvers before enabling DNSSEC.

Show answer and explanation

Correct answers: A, B

Explanation

To enable DNSSEC for a Cloud DNS managed zone, DNSSEC signing must be enabled on the zone, and the DS records must be configured in the domain registrar to establish a chain of trust. These steps ensure that DNS responses are cryptographically validated, preventing tampering or spoofing. Other options, such as custom key management or adjusting TTLs, are unnecessary due to Google Cloud DNS's automated key management and DNSSEC operation mechanisms.

  • A. Correct.

    Enabling DNSSEC signing on the managed zone ensures that DNSSEC is properly configured and the zone's records are cryptographically signed for integrity.

  • B. Correct.

    Publishing the DS records at the domain registrar establishes the chain of trust from the parent zone to the managed zone, a necessary step for DNSSEC functionality.

  • C. Incorrect.

    Google Cloud DNS automatically manages and rotates DNSSEC keys, so there is no need to manually create or import custom keys.

  • D. Incorrect.

    TTL values for DNS records do not need to match any specific DNSSEC requirements. DNSSEC operates independently of record TTL settings.

  • E. Incorrect.

    DNSSEC validation on client resolvers does not need to be disabled. It is unrelated to enabling DNSSEC on the managed zone.

Timed practice exam

Take a Google Professional Cloud Network Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam