DNS Security Practitioner — assessment
- questions
- 15
- to pass
- 80%
- retakes
- Unlimited
- time limit
- None
Covers
- How a Zone Is Signed
- Authenticated Denial
- Key Rollovers
- Constraining Issuance
- The Registrar Layer
- Authoritative Resilience
- Zone Transfer
- Records That Outlive Their Services
Sample question
During a KSK rollover the new key is published and signing, the new DS was never submitted to the parent, and the old key is then removed on schedule. What happens?
- The zone goes bogus for every validating resolver — the parent’s DS names a key that is no longer in the DNSKEY set.Validation requires a published DS matching a key that signs the DNSKEY RRset, and nothing does. The result is SERVFAIL rather than an unsigned answer, so the domain stops resolving rather than merely losing protection.
- The zone is treated as unsigned until the DS is corrected.That would follow from having no DS at all. A DS pointing at a missing key is a broken chain, which is bogus.
- Nothing, until the cached DS expires.The cached DS is what makes resolvers insist on a key that is gone, and the DS is still published at the parent regardless.
- Only resolvers that had not already cached the DNSKEY set are affected.Right about which fail first, and the failure grows rather than stays contained as caches turn over.
Every option carries an explanation, including the wrong ones.
The assessment needs an account.
Passing issues DNS Security Practitioner. A CertaDNS Academy certificate records that you completed a course and passed its assessment on a given date. It is not a professional certification, it is not accredited, and it does not expire.