In DNSSEC, which records are published to establish trust with parent zones?

Prepare for the Infoblox Certification Exam. Utilize our tests featuring diverse questions and detailed explanations. Ace your certification!

Multiple Choice

In DNSSEC, which records are published to establish trust with parent zones?

Explanation:
In DNSSEC, trust between a child zone and its parent is established by publishing a DS (Delegation Signer) record in the parent zone. The DS record contains a digest of the child zone’s DNSKEY, and when the parent is signed, this creates a chain of trust from the parent down to the child. Resolvers verify the DS against the child’s DNSKEY to confirm the linkage and validate responses within the child zone. Without the DS in the parent, there’s no authenticated path from the root to the child zone. The other records—A (address) records, NS (name server) records, and MX (mail exchange) records—are regular DNS records that can exist in a DNSSEC-signed zone, but they do not establish the delegation trust with the parent.

In DNSSEC, trust between a child zone and its parent is established by publishing a DS (Delegation Signer) record in the parent zone. The DS record contains a digest of the child zone’s DNSKEY, and when the parent is signed, this creates a chain of trust from the parent down to the child. Resolvers verify the DS against the child’s DNSKEY to confirm the linkage and validate responses within the child zone. Without the DS in the parent, there’s no authenticated path from the root to the child zone.

The other records—A (address) records, NS (name server) records, and MX (mail exchange) records—are regular DNS records that can exist in a DNSSEC-signed zone, but they do not establish the delegation trust with the parent.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy