• Wrong document? Swap it for free
  • Written by students who passed
  • Immediately available after payment
  • Read online or as PDF
Sell
Where do you study
Your language
Document preview thumbnail
Preview 4 out of 309 pages
Exam (elaborations)

Infoblox DSA DNS Security Associate Study Guide and Practice Test Infoblox DSA DNS Security Associate Certification Exam

Document preview thumbnail
Preview 4 out of 309 pages

Infoblox DSA DNS Security Associate Study Guide and Practice Test Infoblox DSA DNS Security Associate Certification Exam Infoblox DSA DNS Security Associate Study Guide and Practice Test Infoblox DSA DNS Security Associate Certification Exam

Content preview

Infoblox DSA DNS Security Associate Study Guide and
Practice Test


Infoblox DSA DNS Security Associate Certification Exam


Section 1: DNS Security Fundamentals

Question 1 of 1000

Which of the following best describes the primary security weakness of the original DNS
protocol design?

A) It uses UDP port 53, which is easily blocked by firewalls.
B) It lacks built-in authentication and integrity mechanisms.
C) It relies on TCP for zone transfers, which are inherently insecure.
D) It uses a hierarchical naming structure that is difficult to secure.

Correct Answer: B

Rationale: The original DNS protocol was designed for scalability and performance, not security.
It does not include native authentication or integrity verification mechanisms, meaning
responses can be spoofed or tampered with. While UDP port 53 is used, it is not the primary
weakness. TCP is used for zone transfers but that is not the core design flaw. The hierarchical
structure is not inherently insecure. DNS was not designed with security in mind, making it
vulnerable to spoofing and cache poisoning.

Question 2 of 1000

A DNS resolver receives a response that appears to come from an authoritative nameserver, but
the transaction ID matches a query the resolver sent. What type of attack is most likely
occurring?

A) DNS tunneling
B) DNS cache poisoning
C) DNS amplification
D) Domain hijacking

Correct Answer: B

,Rationale: DNS cache poisoning occurs when an attacker injects false DNS records into a
resolver's cache. A common method involves guessing or spoofing the transaction ID and source
port of a legitimate query. The resolver believes the forged response is legitimate and caches it,
redirecting future queries to malicious IP addresses. DNS tunneling involves hiding data in DNS
queries. DNS amplification is a DDoS technique. Domain hijacking involves taking control of a
domain registration.

Question 3 of 1000

Which DNS record type is used to specify the mail servers responsible for accepting email on
behalf of a domain?

A) A
B) MX
C) CNAME
D) TXT

Correct Answer: B

Rationale: The MX (Mail Exchange) record specifies the mail servers responsible for accepting
email messages on behalf of a domain. A records map hostnames to IPv4 addresses. CNAME
records create aliases. TXT records hold arbitrary text data, often used for SPF, DKIM, and
DMARC email security configurations. Understanding record types is fundamental to DNS
security analysis.

Question 4 of 1000

What is the primary purpose of the DNS root zone?

A) To store all domain names and their IP addresses.
B) To provide the starting point for DNS resolution by directing queries to the appropriate TLD
nameservers.
C) To authenticate DNSSEC signatures for all domains.
D) To cache frequently requested DNS records for faster resolution.

Correct Answer: B

Rationale: The DNS root zone is the top of the DNS hierarchy. It does not contain records for
every domain; instead, it contains delegations to Top-Level Domain (TLD) nameservers (such as
.com, .org, .net). When a resolver starts resolution, it queries a root server, which refers it to the
appropriate TLD server. The root zone also contains the root trust anchor for DNSSEC. It does
not cache records; that is the resolver's function.

Question 5 of 1000

,Which of the following is a legitimate use of DNS TXT records that also has security
implications?

A) Storing the IP address of the web server.
B) Implementing SPF, DKIM, and DMARC for email authentication.
C) Defining the canonical name for an alias.
D) Specifying the mail exchange server.

Correct Answer: B

Rationale: TXT records are used to publish SPF (Sender Policy Framework), DKIM (DomainKeys
Identified Mail), and DMARC (Domain-based Message Authentication, Reporting, and
Conformance) policies. These help prevent email spoofing and phishing. While TXT records can
contain other data, their use for email authentication is a critical security control. A records
store IP addresses. CNAME defines aliases. MX specifies mail servers.

Section 2: Domain Hijacking

Question 6 of 1000

What distinguishes domain hijacking from DNS hijacking?

A) Domain hijacking targets the domain registration, while DNS hijacking targets DNS resolution.
B) Domain hijacking uses malware, while DNS hijacking uses social engineering.
C) Domain hijacking only affects subdomains, while DNS hijacking affects the root domain.
D) Domain hijacking is a type of DDoS attack, while DNS hijacking is a type of phishing.

Correct Answer: A

Rationale: Domain hijacking involves an attacker gaining control of a domain's registration,
often by compromising the registrar account or exploiting a transfer process. This gives them
full control over the domain's DNS settings. DNS hijacking, in contrast, involves intercepting or
manipulating DNS resolution, such as by changing DNS settings on a router or compromising a
DNS server. Both can redirect users, but the attack vector and scope differ.

Question 7 of 1000

In a "Sitting Ducks" attack, what misconfiguration do attackers exploit?

A) Open DNS resolvers that allow recursive queries from any source.
B) Domains with dangling CNAME records pointing to unclaimed cloud services.
C) DNSSEC zones without a valid trust anchor.
D) DNS servers that permit zone transfers to any IP address.

Correct Answer: B

, Rationale: The "Sitting Ducks" attack exploits domains that have CNAME records pointing to
cloud services or hosting providers that are no longer in use or have been abandoned. Attackers
can claim the abandoned resource and effectively take control of the domain's DNS resolution.
This is a form of domain hijacking via DNS misconfiguration. Open resolvers relate to
amplification attacks. Zone transfers are a separate misconfiguration.

Question 8 of 1000

Which of the following is the most effective mitigation against domain hijacking through
registrar account compromise?

A) Implementing DNSSEC on all zones.
B) Enabling multi-factor authentication (MFA) on the registrar account.
C) Using a third-party DNS provider.
D) Configuring Response Policy Zones (RPZ).

Correct Answer: B

Rationale: Domain hijacking via registrar compromise often occurs because attackers gain
access to the registrar account through stolen credentials. Enabling MFA adds a critical layer of
protection, making it significantly harder for attackers to access the account even if they obtain
the password. DNSSEC protects against cache poisoning, not registrar compromise. Third-party
DNS providers do not control registrar access. RPZ is used for blocking malicious domains, not
protecting registrar accounts.

Question 9 of 1000

What is a "dangling DNS record"?

A) A DNS record that has expired but is still in the cache.
B) A DNS record that points to a resource that no longer exists or is no longer controlled by the
domain owner.
C) A DNS record with an invalid TTL value.
D) A DNS record that has not been signed with DNSSEC.

Correct Answer: B

Rationale: A dangling DNS record is one that points to a resource (such as an IP address, CNAME
target, or cloud service) that has been decommissioned or is no longer under the control of the
domain owner. Attackers can exploit these records by claiming the abandoned resource,
thereby gaining control over the domain's resolution. This is a common vector for subdomain
takeover.

Question 10 of 1000

Document information

Uploaded on
September 12, 2026
Number of pages
309
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$22.49

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Sold
0
Followers
0
Items
164
Last sold
-



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions