exam questions

Exam AWS Certified Security - Specialty SCS-C02 All Questions

View all questions & answers for the AWS Certified Security - Specialty SCS-C02 exam

Exam AWS Certified Security - Specialty SCS-C02 topic 1 question 185 discussion

A company needs to implement DNS Security Extensions (DNSSEC) for a specific subdomain. The subdomain is already registered with Amazon Route 53. A security engineer has enabled DNSSEC signing and has created a key-signing key (KSK). When the security engineer tries to test the configuration, the security engineer receives an error for a broken trust chain.

What should the security engineer do to resolve this error?

  • A. Replace the KSK with a zone-signing key (ZSK).
  • B. Deactivate and then activate the KSK.
  • C. Create a Delegation Signer (DS) record in the parent hosted zone.
  • D. Create a Delegation Signer (DS) record in the subdomain.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
mikelord
Highly Voted 6 months, 3 weeks ago
Selected Answer: C
DS record must be created in the parent hosted zone to properly link the DNSSEC configuration of the subdomain with its parent zone
upvoted 5 times
...
IPLogic
Most Recent 4 months, 3 weeks ago
Selected Answer: C
To resolve the broken trust chain error, the security engineer should: C. Create a Delegation Signer (DS) record in the parent hosted zone. The DS record in the parent zone is essential for establishing the chain of trust between the parent and the child zone. This record contains a hash of the child zone’s DNSKEY, which allows DNS resolvers to verify the authenticity of the DNSKEY in the child zone.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago