DNS Security Practitioner
Operating a signed zone: key roles and algorithms, the rollover that breaks delegations, authenticated denial and zone walking, CAA against ACME, registrar locks, resilience, and the dangling records that outlive the services behind them.
- lessons
- 19
- total
- 3 h
- level
- Intermediate
Assumes Domain Security Fundamentals.
You will be able to
- Read a zone’s key set and say whether it uses separate keys or one
- Choose a signing algorithm, and say what to migrate off
- Perform a KSK rollover without breaking the delegation
- Say what an attacker learns from your authenticated denial
- Write a CAA set that constrains issuance without blocking your own ACME client
- Distinguish a transfer lock from a registry lock in RDAP output
- Find dangling CNAME, NS and MX records and retire services safely
Syllabus
1. How a Zone Is Signed
Key roles, the algorithms worth using, and the signature window that expires.
2. Authenticated Denial
Why NSEC enumerates your zone, what NSEC3 fixed, and what replaced both.
3. Key Rollovers
The two rollovers, the DS update that breaks delegations, and automating it.
4. Constraining Issuance
Reading a CAA set, and writing one that does not block your own ACME client.
5. The Registrar Layer
Reading lock state from RDAP, and the account that outranks every DNS control.
6. Authoritative Resilience
Single-provider risk, running two, and what has to stay in sync between them.
7. Zone Transfer
AXFR, TSIG and NOTIFY, and what an open transfer hands to anyone who asks.
8. Records That Outlive Their Services
Dangling CNAME, NS and MX, and the retirement discipline that prevents all three.
9. Final assessment
15 scenario questions · 80% to pass · unlimited retakes
What the assessment covers
DNS Security Practitioner
- Complete every lesson in DNS Security Practitioner
- Pass the DNS Security Practitioner assessment with at least 80%
CertaDNS Engineering · last reviewed