Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
An enterprise hosts its primary domain in a Google Cloud DNS public managed zone. A security engineer must configure Domain Name System Security Extensions (DNSSEC) to protect client resolvers from DNS spoofing and cache poisoning attacks. The solution must establish a verified chain of trust with the third-party domain registrar and define a zero-downtime rotation procedure for the Key Signing Key (KSK).
Which procedure should the security engineer implement?
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.