exam questions

Exam 70-741 All Questions

View all questions & answers for the 70-741 exam

Exam 70-741 topic 1 question 106 discussion

Actual exam question from Microsoft's 70-741
Question #: 106
Topic #: 1
[All 70-741 Questions]

You have two DNS servers named Server1 and Server2.
All client computers run Windows 10 and are configured to use Server1 for DNS name resolution.
Server2 hosts a primary zone named contoso.com.
Your network recently experienced several DNS spoofing attacks on the contoso.com zone.
You need to prevent further attacks from succeeding.
What should you do on Server2?

  • A. Sign the contoso.com zone.
  • B. Configure Response Rate Limiting (RRL).
  • C. Configure DNS-based Authentication of Named Entities (DANE) for the contoso.com zone.
  • D. Configure the contoso.com zone to be Active Directory-integrated.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
TMW
Highly Voted 5 years, 6 months ago
this one is correct. in addition to cache locking, you can use DNSSEC to prevent spoofing: https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/dn593670(v%3Dws.11)
upvoted 12 times
...
ITGEEK
Highly Voted 4 years, 11 months ago
DNSSEC is the correct answer
upvoted 5 times
TA77
4 years, 2 months ago
There is no DNSSEC option in the provided answers!!!
upvoted 1 times
V1980
4 years, 1 month ago
DANE = DNSSEC
upvoted 3 times
jmlbrns45
4 years ago
DANE deals with signed certificates, not zones. so DANE does not mean DNSSEC in the zone sense.
upvoted 3 times
...
...
...
...
panda
Most Recent 3 years, 10 months ago
C. DANE can be excluded. If you experience that clients request to incorrect DNS server, to prevent from tihs, you must use DANE.
upvoted 1 times
...
panda
3 years, 10 months ago
I think A (sign) is correct. To begin with DNS spoofing attacks changes DNS record. In this time DNS spoofing attacks spoof nobody. When client requests changed DNS record, DNS send it to client. In this time client is spoofed by the record. Namely, DNS spoofing attacks change DNS record directry and spoof clients indirectry. Therefore to prevent from tihs attack you must shild DNS record, not client.
upvoted 1 times
...
panda
4 years ago
The given answer (question 22 page 37) is B (RRL). The given answer (question 106 page 22) is A (sign). DANE prevents clients from requesting to fake DNS servers.(*1) RRL prevents DNS servers from DDoS attacks.(*1) Signing prevents clients to receie responses from fake DNS server1.(*2) (*1) https://docs.microsoft.com/en-us/windows-server/networking/dns/what-s-new-in-dns-server (*2) https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/dn593670(v%3Dws.11)
upvoted 4 times
...
TA77
4 years, 3 months ago
Spoofing: someone or something pretends to be something else to gain access to a system. DNS spoofing: is the practice of assuming the DNS name of another system either by corrupting a name service cache or by compromising a DNS server for a valid domain. Answer is correct. Reference: https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/dn593670(v%3Dws.11)
upvoted 2 times
...
Kamikazekiller
4 years, 5 months ago
A. Sign the contoso.com zone.
upvoted 2 times
...
LeonSKanady
4 years, 6 months ago
Guys - Bonna, TMW , ITGEEK, Antony are correct... Correct answer is : A Its DNSSEC that can protect against spoofing attack. Read the below reference. " Improved security: Signing with DNSSEC can protect you from DNS spoofing attacks. " Link: https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/dn593637(v%3dws.11)
upvoted 1 times
V1980
4 years, 1 month ago
Lol again with the 2 answers. Correct answer: A which is SIGN THE ZONE, its DNSEC that can protec...answer C! Cmon man
upvoted 2 times
...
...
Ant0ny
4 years, 10 months ago
Actually looking more into this, the correct answer is A sign the zone or in other words DNSSEC
upvoted 5 times
...
Ant0ny
4 years, 10 months ago
The answer is DANE which is built on DNSSEC
upvoted 5 times
...
TMW
5 years, 6 months ago
RRL is to prevent DDOS attacks. The answer I would be looking for is cache locking, but it is not one of the answers....
upvoted 3 times
...
[Removed]
5 years, 6 months ago
I beleive the answer for this is Response Rate Limitting RRL, or Response Rate Limiting, tries to extenuate the DNS amplification attacks. In a DNS amplification attack, the attackers forge the IP address of the victim network and send a lot of queries to the DNS servers. The traditional DNS server responds back to all the queries it receives and as a result the victim network gets a huge amount of unwanted DNS responses . https://blogs.technet.microsoft.com/teamdhcp/2015/08/28/response-rate-limiting-in-windows-dns-server/
upvoted 1 times
algerianphoenix
4 years, 4 months ago
RRL is to protect from DDoS, while Signing is useful against Spoofing.
upvoted 6 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago