exam questions

Exam SY0-501 All Questions

View all questions & answers for the SY0-501 exam

Exam SY0-501 topic 1 question 65 discussion

Actual exam question from CompTIA's SY0-501
Question #: 65
Topic #: 1
[All SY0-501 Questions]

An organization wishes to provide better security for its name resolution services. Which of the following technologies BEST supports the deployment of DNSSEC at the organization?

  • A. LDAP
  • B. TPM
  • C. TLS
  • D. SSL
  • E. PKI
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
JohnMArston54
Highly Voted 5 years, 2 months ago
PKI is part of the DNSSEC, as everyone has said it is required. But the question asks about providing better security for DNSSEC. PKI provides the authentication, while TLS provides the secure transmission?
upvoted 10 times
p3n15okay
3 years, 9 months ago
Correct. CompTIA views PKI at least in this context as a means of authentication
upvoted 1 times
...
...
Mohawk
Highly Voted 4 years, 2 months ago
My trick, every time I see esc or s at the end, it is TLS --as in FTPS which is FTP over TLS. in this case DNS over TLS.
upvoted 6 times
...
slackbot
Most Recent 5 months, 2 weeks ago
Selected Answer: E
DNSSEC uses certificates ONLY. DNS over TCP uses TLS. they are asking for DNSSEC, not for DoT.
upvoted 1 times
...
boydmwanza
3 years, 10 months ago
Ssl =tls therefore both cant be the answer. PKI IT IS
upvoted 1 times
dylanf6
3 years, 10 months ago
Part of what makes the actual exam so difficult is the fact that there are multiple answers that could be correct. However, the "BEST" is what you should focus on. TLS is essentially the "new and improved" SSL, making it the "BEST" of the options.
upvoted 1 times
...
...
Dion79
3 years, 10 months ago
I like provided answer. In any case, you should be aware that the DNSSEConlyauthorizes name resolution; the data transmitted receives no protection. This means it’s essential to combine this technology with encrypted transmission protocols like TSL. Reference 1. https://www.ionos.com/digitalguide/server/know-how/dnssec-internet-standards-for-authenticated-name-resolution/
upvoted 1 times
...
amerigo
4 years, 2 months ago
https://www.verisign.com/en_US/domain-names/dnssec/how-dnssec-works/index.xhtml
upvoted 1 times
...
sec__
4 years, 5 months ago
the question is asking how will it be deployed and TCP is the only protocol that has anything to do with commmunicating with other networks
upvoted 1 times
...
Not_My_Name
4 years, 7 months ago
Answer is "E". DNSSEC used Digital Signatures (which is part of PKI). DoT (DNS over TLS) uses TLS. These are completely different beasts.
upvoted 3 times
...
ShinyBluePen
4 years, 7 months ago
I guess PKI is not a "technology"?
upvoted 1 times
nakres64
4 years, 2 months ago
It is a technology.. "A Public Key Infrastructure (PKI) is a group of technologies used to request, create, manage, store, distribute, and revoke digital certificates."
upvoted 1 times
...
...
Don_H
4 years, 9 months ago
the answer is E. note, DNSSEC already has security measures to prevent against DNS cache poisoning. To provide better security, PKI is needed to attach signatures to DNS query responses.
upvoted 4 times
Teza
4 years, 8 months ago
I agree with you on this. It needs a certificate to do this and the only option available for this is PKI. I wish the moderators can commit to reviewing and updating the answers. The information on this site should be reliable enough
upvoted 2 times
...
...
TeeTime87
4 years, 10 months ago
E. PKI.....My reasoning, is that when you are deploying something you are assigning something, which I believe is the PKI being assigned to DNSSec so that a TLS connection can then be made. Also, Public Key Infrastructure (PKI) is a technology for authenticating users and devices in the digital world.....TLS is a security protocol that provides privacy and data integrity over Internet communications. Just my thoughts.
upvoted 2 times
...
avgeek63
4 years, 10 months ago
"**supports** the deployment of DNSSEC". I interpreted this to mean, "yes, we're doing DNSSEC, but what goes best with it". Also, DNSSEC secures DNS at the application layer, but TLS will secure DNS at the underlying/supporting transport layer. I think these kinds of semantics really matter on this exam, which is a bit unfair
upvoted 1 times
...
Hot_156
4 years, 10 months ago
This is the question, -Which of the following technologies BEST supports the deployment of DNSSEC at the organization? so, how TLS\SSL would support the deployment?
upvoted 3 times
Hot_156
4 years, 10 months ago
from the GAGC book, One of the primary methods of preventing DNS cache poisoning is with Domain Name System Security Extensions ( DNSSEC ). DNSSEC is a suite of extensions to DNS that provides validation for DNS responses. It adds a digital signature to each record that provides data integrity. If a DNS server receives a DNSSEC-enabled response with digitally signed records, the DNS server knows that the response is valid. based on that DNSSEC uses digital signatures! so it needs PKI to be able to wrok with Digital Signatures
upvoted 3 times
...
...
kdce
4 years, 11 months ago
C, TLS is more secure
upvoted 1 times
...
Meredith
4 years, 11 months ago
I agree that the answer should be (E), PKI. "[DNSSEC] allows you to verify the responses that you’re getting from a DNS server. You can make sure that it’s really coming from the correct origin, and you can make sure the information that you’re receiving is exactly what was sent from the DNS server. DNSSEC does this using public key cryptography." https://www.professormesser.com/security-plus/sy0-501/secure-protocols/
upvoted 4 times
...
renegade_xt
4 years, 11 months ago
TLS https://wiki.mozilla.org/Security/DNSSEC-TLS-details
upvoted 1 times
...
MelvinJohn
5 years ago
C - The question states "BETTER SECURITY for its name resolution" - PKI doesn't encrypt DNS records - it only adds a digital signature. TLS uses PKI certificates to authenticate parties communicating with each other. So TLS incorporates PKI. therefore when you use TLS you are using PKI as well. BETTER SECURITY.
upvoted 5 times
andy_sunday
4 years, 12 months ago
the question says "BEST SUPPORTS DNSSEC DEPLOYMENT" - Ans is PKI. DNS over TLS is different from DNSSEC.
upvoted 3 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago