Study. uk . com
  1. Home
  2. All questions
  3. Question 292

CISSP study material · question 292 of 500

An administrator plans to rely on DNSSEC to protect zone transfers and dynamic updates between name servers. What does RFC 4033 say?

  1. Those operations are protected once both servers hold the same trust anchor.
  2. Those operations are protected only where the zone uses an authenticated denial-of-existence record.
  3. Those operations were not the target of the extensions; separate message authentication schemes address them.
  4. Those operations are protected only in the secure state.
Show the answer

Answer: C. Those operations were not the target of the extensions; separate message authentication schemes address them.

Zone transfer and dynamic update were never the target of these mechanisms; other message authentication schemes were defined to secure those transactions.

Source: RFC 4033 (IETF) — RFC 4033 > 4. Services Not Provided by DNS Security

Challenge yourself on this topic → Study as cards