Domain Trust Architecture — assessment
- questions
- 15
- to pass
- 80%
- retakes
- Unlimited
- time limit
- None
Covers
- What Domain Trust Means
- The Controls as One System
- Order of Operations
- Assessing an Estate
- Prioritising
- Sustaining It
Sample question
A customer is deceived by a homograph domain that has valid TLS, its own correct DMARC record, and a signed zone. Which of the four surfaces failed?
- Perception — every protocol check passed correctly, on a domain the attacker genuinely controls.Identity, integrity and transport all did their jobs: the message really is from that domain, unmodified, over TLS. What failed is the gap between what the protocols determined and what a human saw — the only surface defended by a person rather than a check.
- Identity, because the brand was impersonated.Identity controls answer whether a message is from the party it claims. It is, and the deception is in how the name reads.
- Integrity, because the content was not genuine.The content is exactly what its sender published, and the signatures prove it.
- Transport, because TLS failed to prevent the deception.TLS worked. It secures the hop and says nothing about who the other end is to a human reader.
Every option carries an explanation, including the wrong ones.
The assessment needs an account.
Passing issues Domain Trust Architecture. A CertaDNS Academy certificate records that you completed a course and passed its assessment on a given date. It is not a professional certification, it is not accredited, and it does not expire.