- Home
- All questions
- Question 287
CISSP study material · question 287 of 500
A team proposes DNSSEC to stop an eavesdropper reading which sites employees look up. Why does this fail?
Show the answer
Answer: D. DNSSEC supplies origin authentication and integrity plus key distribution, and deliberately provides no confidentiality.
The extensions authenticate the origin of records and protect their integrity, and distribute keys; secrecy of the query or answer is outside what they do.
Source: RFC 4033 (IETF) — RFC 4033 > 1. Introduction