- Home
- All questions
- Question 288
CISSP study material · question 288 of 500
How is a DNSSEC authentication chain built, according to RFC 4033?
Show the answer
Answer: B. Alternating DNSKEY record sets and delegation signer record sets, each delegation signer holding a hash that authenticates the next key.
An authentication chain is an alternating sequence of DNSKEY record sets and delegation signer record sets, with each delegation signer record containing a hash that authenticates the next key.
Source: RFC 4033 (IETF) — RFC 4033 > 2. Definitions of Important DNSSEC Terms