Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
An enterprise hosts its primary domain in a Google Cloud DNS public managed zone. A security engineer must configure Domain Name System Security Extensions (DNSSEC) to protect client resolvers from DNS spoofing and cache poisoning attacks. The solution must establish a verified chain of trust with the third-party domain registrar and define a zero-downtime rotation procedure for the Key Signing Key (KSK).
Which procedure should the security engineer implement?
Domain Name System Security Extensions (DNSSEC) provides cryptographic authentication of DNS data to prevent DNS spoofing, cache poisoning, and man-in-the-middle tampering. In Google Cloud DNS, enabling DNSSEC causes the service to automatically generate Key Signing Keys (KSK) and Zone Signing Keys (ZSK), sign the resource record sets (RRsets) with RRSIG records, and generate Delegation Signer (DS) records.
This approach strictly complies with RFC specifications and DNSSEC standards for establishing a verifiable delegation chain while preventing service outages during public key transitions.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.