exam questions

Exam CCSP All Questions

View all questions & answers for the CCSP exam

Exam CCSP topic 1 question 124 discussion

Actual exam question from ISC's CCSP
Question #: 124
Topic #: 1
[All CCSP Questions]

What changes are necessary to application code in order to implement DNSSEC?

  • A. Adding encryption modules
  • B. Implementing certificate validations
  • C. Additional DNS lookups
  • D. No changes are needed.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️
To implement DNSSEC, no additional changes are needed to applications or their code because the integrity checks are all performed at the system level.

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
MaciekMT
2 days, 2 hours ago
Selected Answer: D
DNSSEC (Domain Name System Security Extensions) is handled at the DNS infrastructure and resolver level, rather than at the application code level. As long as the underlying DNS resolvers and infrastructure support DNSSEC, applications typically don’t require any additional changes to start benefiting from the secure DNS lookups.
upvoted 1 times
...
ArashV
3 weeks, 5 days ago
Selected Answer: C
It's very unlikely this question is asked just to be pointless and with no action needed. I think as per specified by contributor DA95, option C is correct.
upvoted 1 times
...
nzboy123
1 month, 3 weeks ago
Selected Answer: C
To facilitate signature validation, DNSSEC adds a few new DNS record types: RRSIG - Contains a cryptographic signature DNSKEY - Contains a public signing key DS - Contains the hash of a DNSKEY record NSEC and NSEC3 - For explicit denial-of-existence of a DNS record CDNSKEY and CDS - For a child zone requesting updates to DS record(s) in the parent zone.
upvoted 1 times
...
DA95
2 months, 1 week ago
In order to implement DNSSEC, some changes to application code may be necessary. DNSSEC is a security extension to the Domain Name System (DNS) that provides authentication for DNS lookups. To implement DNSSEC, application code may need to be updated to perform additional DNS lookups in order to verify the authenticity of DNS records. This may involve adding code to perform cryptographic operations in order to validate DNSSEC signatures. Therefore, the correct answer is option C, "Additional DNS lookups."
upvoted 3 times
...
akg001
9 months, 1 week ago
Selected Answer: D
D. No changes are needed.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago