Infoblox DSA DNS Security Associate Study Guide and
Practice Test
Infoblox DSA DNS Security Associate Certification Exam
Section 1: DNS Security Fundamentals
Question 1 of 1000
Which of the following best describes the primary security weakness of the original DNS
protocol design?
A) It uses UDP port 53, which is easily blocked by firewalls.
B) It lacks built-in authentication and integrity mechanisms.
C) It relies on TCP for zone transfers, which are inherently insecure.
D) It uses a hierarchical naming structure that is difficult to secure.
Correct Answer: B
Rationale: The original DNS protocol was designed for scalability and performance, not security.
It does not include native authentication or integrity verification mechanisms, meaning
responses can be spoofed or tampered with. While UDP port 53 is used, it is not the primary
weakness. TCP is used for zone transfers but that is not the core design flaw. The hierarchical
structure is not inherently insecure. DNS was not designed with security in mind, making it
vulnerable to spoofing and cache poisoning.
Question 2 of 1000
A DNS resolver receives a response that appears to come from an authoritative nameserver, but
the transaction ID matches a query the resolver sent. What type of attack is most likely
occurring?
A) DNS tunneling
B) DNS cache poisoning
C) DNS amplification
D) Domain hijacking
Correct Answer: B
,Rationale: DNS cache poisoning occurs when an attacker injects false DNS records into a
resolver's cache. A common method involves guessing or spoofing the transaction ID and source
port of a legitimate query. The resolver believes the forged response is legitimate and caches it,
redirecting future queries to malicious IP addresses. DNS tunneling involves hiding data in DNS
queries. DNS amplification is a DDoS technique. Domain hijacking involves taking control of a
domain registration.
Question 3 of 1000
Which DNS record type is used to specify the mail servers responsible for accepting email on
behalf of a domain?
A) A
B) MX
C) CNAME
D) TXT
Correct Answer: B
Rationale: The MX (Mail Exchange) record specifies the mail servers responsible for accepting
email messages on behalf of a domain. A records map hostnames to IPv4 addresses. CNAME
records create aliases. TXT records hold arbitrary text data, often used for SPF, DKIM, and
DMARC email security configurations. Understanding record types is fundamental to DNS
security analysis.
Question 4 of 1000
What is the primary purpose of the DNS root zone?
A) To store all domain names and their IP addresses.
B) To provide the starting point for DNS resolution by directing queries to the appropriate TLD
nameservers.
C) To authenticate DNSSEC signatures for all domains.
D) To cache frequently requested DNS records for faster resolution.
Correct Answer: B
Rationale: The DNS root zone is the top of the DNS hierarchy. It does not contain records for
every domain; instead, it contains delegations to Top-Level Domain (TLD) nameservers (such as
.com, .org, .net). When a resolver starts resolution, it queries a root server, which refers it to the
appropriate TLD server. The root zone also contains the root trust anchor for DNSSEC. It does
not cache records; that is the resolver's function.
Question 5 of 1000
,Which of the following is a legitimate use of DNS TXT records that also has security
implications?
A) Storing the IP address of the web server.
B) Implementing SPF, DKIM, and DMARC for email authentication.
C) Defining the canonical name for an alias.
D) Specifying the mail exchange server.
Correct Answer: B
Rationale: TXT records are used to publish SPF (Sender Policy Framework), DKIM (DomainKeys
Identified Mail), and DMARC (Domain-based Message Authentication, Reporting, and
Conformance) policies. These help prevent email spoofing and phishing. While TXT records can
contain other data, their use for email authentication is a critical security control. A records
store IP addresses. CNAME defines aliases. MX specifies mail servers.
Section 2: Domain Hijacking
Question 6 of 1000
What distinguishes domain hijacking from DNS hijacking?
A) Domain hijacking targets the domain registration, while DNS hijacking targets DNS resolution.
B) Domain hijacking uses malware, while DNS hijacking uses social engineering.
C) Domain hijacking only affects subdomains, while DNS hijacking affects the root domain.
D) Domain hijacking is a type of DDoS attack, while DNS hijacking is a type of phishing.
Correct Answer: A
Rationale: Domain hijacking involves an attacker gaining control of a domain's registration,
often by compromising the registrar account or exploiting a transfer process. This gives them
full control over the domain's DNS settings. DNS hijacking, in contrast, involves intercepting or
manipulating DNS resolution, such as by changing DNS settings on a router or compromising a
DNS server. Both can redirect users, but the attack vector and scope differ.
Question 7 of 1000
In a "Sitting Ducks" attack, what misconfiguration do attackers exploit?
A) Open DNS resolvers that allow recursive queries from any source.
B) Domains with dangling CNAME records pointing to unclaimed cloud services.
C) DNSSEC zones without a valid trust anchor.
D) DNS servers that permit zone transfers to any IP address.
Correct Answer: B
, Rationale: The "Sitting Ducks" attack exploits domains that have CNAME records pointing to
cloud services or hosting providers that are no longer in use or have been abandoned. Attackers
can claim the abandoned resource and effectively take control of the domain's DNS resolution.
This is a form of domain hijacking via DNS misconfiguration. Open resolvers relate to
amplification attacks. Zone transfers are a separate misconfiguration.
Question 8 of 1000
Which of the following is the most effective mitigation against domain hijacking through
registrar account compromise?
A) Implementing DNSSEC on all zones.
B) Enabling multi-factor authentication (MFA) on the registrar account.
C) Using a third-party DNS provider.
D) Configuring Response Policy Zones (RPZ).
Correct Answer: B
Rationale: Domain hijacking via registrar compromise often occurs because attackers gain
access to the registrar account through stolen credentials. Enabling MFA adds a critical layer of
protection, making it significantly harder for attackers to access the account even if they obtain
the password. DNSSEC protects against cache poisoning, not registrar compromise. Third-party
DNS providers do not control registrar access. RPZ is used for blocking malicious domains, not
protecting registrar accounts.
Question 9 of 1000
What is a "dangling DNS record"?
A) A DNS record that has expired but is still in the cache.
B) A DNS record that points to a resource that no longer exists or is no longer controlled by the
domain owner.
C) A DNS record with an invalid TTL value.
D) A DNS record that has not been signed with DNSSEC.
Correct Answer: B
Rationale: A dangling DNS record is one that points to a resource (such as an IP address, CNAME
target, or cloud service) that has been decommissioned or is no longer under the control of the
domain owner. Attackers can exploit these records by claiming the abandoned resource,
thereby gaining control over the domain's resolution. This is a common vector for subdomain
takeover.
Question 10 of 1000
Practice Test
Infoblox DSA DNS Security Associate Certification Exam
Section 1: DNS Security Fundamentals
Question 1 of 1000
Which of the following best describes the primary security weakness of the original DNS
protocol design?
A) It uses UDP port 53, which is easily blocked by firewalls.
B) It lacks built-in authentication and integrity mechanisms.
C) It relies on TCP for zone transfers, which are inherently insecure.
D) It uses a hierarchical naming structure that is difficult to secure.
Correct Answer: B
Rationale: The original DNS protocol was designed for scalability and performance, not security.
It does not include native authentication or integrity verification mechanisms, meaning
responses can be spoofed or tampered with. While UDP port 53 is used, it is not the primary
weakness. TCP is used for zone transfers but that is not the core design flaw. The hierarchical
structure is not inherently insecure. DNS was not designed with security in mind, making it
vulnerable to spoofing and cache poisoning.
Question 2 of 1000
A DNS resolver receives a response that appears to come from an authoritative nameserver, but
the transaction ID matches a query the resolver sent. What type of attack is most likely
occurring?
A) DNS tunneling
B) DNS cache poisoning
C) DNS amplification
D) Domain hijacking
Correct Answer: B
,Rationale: DNS cache poisoning occurs when an attacker injects false DNS records into a
resolver's cache. A common method involves guessing or spoofing the transaction ID and source
port of a legitimate query. The resolver believes the forged response is legitimate and caches it,
redirecting future queries to malicious IP addresses. DNS tunneling involves hiding data in DNS
queries. DNS amplification is a DDoS technique. Domain hijacking involves taking control of a
domain registration.
Question 3 of 1000
Which DNS record type is used to specify the mail servers responsible for accepting email on
behalf of a domain?
A) A
B) MX
C) CNAME
D) TXT
Correct Answer: B
Rationale: The MX (Mail Exchange) record specifies the mail servers responsible for accepting
email messages on behalf of a domain. A records map hostnames to IPv4 addresses. CNAME
records create aliases. TXT records hold arbitrary text data, often used for SPF, DKIM, and
DMARC email security configurations. Understanding record types is fundamental to DNS
security analysis.
Question 4 of 1000
What is the primary purpose of the DNS root zone?
A) To store all domain names and their IP addresses.
B) To provide the starting point for DNS resolution by directing queries to the appropriate TLD
nameservers.
C) To authenticate DNSSEC signatures for all domains.
D) To cache frequently requested DNS records for faster resolution.
Correct Answer: B
Rationale: The DNS root zone is the top of the DNS hierarchy. It does not contain records for
every domain; instead, it contains delegations to Top-Level Domain (TLD) nameservers (such as
.com, .org, .net). When a resolver starts resolution, it queries a root server, which refers it to the
appropriate TLD server. The root zone also contains the root trust anchor for DNSSEC. It does
not cache records; that is the resolver's function.
Question 5 of 1000
,Which of the following is a legitimate use of DNS TXT records that also has security
implications?
A) Storing the IP address of the web server.
B) Implementing SPF, DKIM, and DMARC for email authentication.
C) Defining the canonical name for an alias.
D) Specifying the mail exchange server.
Correct Answer: B
Rationale: TXT records are used to publish SPF (Sender Policy Framework), DKIM (DomainKeys
Identified Mail), and DMARC (Domain-based Message Authentication, Reporting, and
Conformance) policies. These help prevent email spoofing and phishing. While TXT records can
contain other data, their use for email authentication is a critical security control. A records
store IP addresses. CNAME defines aliases. MX specifies mail servers.
Section 2: Domain Hijacking
Question 6 of 1000
What distinguishes domain hijacking from DNS hijacking?
A) Domain hijacking targets the domain registration, while DNS hijacking targets DNS resolution.
B) Domain hijacking uses malware, while DNS hijacking uses social engineering.
C) Domain hijacking only affects subdomains, while DNS hijacking affects the root domain.
D) Domain hijacking is a type of DDoS attack, while DNS hijacking is a type of phishing.
Correct Answer: A
Rationale: Domain hijacking involves an attacker gaining control of a domain's registration,
often by compromising the registrar account or exploiting a transfer process. This gives them
full control over the domain's DNS settings. DNS hijacking, in contrast, involves intercepting or
manipulating DNS resolution, such as by changing DNS settings on a router or compromising a
DNS server. Both can redirect users, but the attack vector and scope differ.
Question 7 of 1000
In a "Sitting Ducks" attack, what misconfiguration do attackers exploit?
A) Open DNS resolvers that allow recursive queries from any source.
B) Domains with dangling CNAME records pointing to unclaimed cloud services.
C) DNSSEC zones without a valid trust anchor.
D) DNS servers that permit zone transfers to any IP address.
Correct Answer: B
, Rationale: The "Sitting Ducks" attack exploits domains that have CNAME records pointing to
cloud services or hosting providers that are no longer in use or have been abandoned. Attackers
can claim the abandoned resource and effectively take control of the domain's DNS resolution.
This is a form of domain hijacking via DNS misconfiguration. Open resolvers relate to
amplification attacks. Zone transfers are a separate misconfiguration.
Question 8 of 1000
Which of the following is the most effective mitigation against domain hijacking through
registrar account compromise?
A) Implementing DNSSEC on all zones.
B) Enabling multi-factor authentication (MFA) on the registrar account.
C) Using a third-party DNS provider.
D) Configuring Response Policy Zones (RPZ).
Correct Answer: B
Rationale: Domain hijacking via registrar compromise often occurs because attackers gain
access to the registrar account through stolen credentials. Enabling MFA adds a critical layer of
protection, making it significantly harder for attackers to access the account even if they obtain
the password. DNSSEC protects against cache poisoning, not registrar compromise. Third-party
DNS providers do not control registrar access. RPZ is used for blocking malicious domains, not
protecting registrar accounts.
Question 9 of 1000
What is a "dangling DNS record"?
A) A DNS record that has expired but is still in the cache.
B) A DNS record that points to a resource that no longer exists or is no longer controlled by the
domain owner.
C) A DNS record with an invalid TTL value.
D) A DNS record that has not been signed with DNSSEC.
Correct Answer: B
Rationale: A dangling DNS record is one that points to a resource (such as an IP address, CNAME
target, or cloud service) that has been decommissioned or is no longer under the control of the
domain owner. Attackers can exploit these records by claiming the abandoned resource,
thereby gaining control over the domain's resolution. This is a common vector for subdomain
takeover.
Question 10 of 1000