Better Security for Name Resolution Services | DNSSEC Deployment Support | SY0-601 Exam | CompTIA

DNSSEC Deployment Support

Prev Question Next Question

Question

An organization wishes to provide better security for its name resolution services.

Which of the following technologies BEST supports the deployment of DNSSEC at the organization?

Answers

Explanations

Click on the arrows to vote for the correct answer

A. B. C. D. E.

C.

The technology that best supports the deployment of DNSSEC (Domain Name System Security Extensions) is PKI (Public Key Infrastructure).

DNSSEC is used to provide integrity and authenticity to the DNS name resolution process. It uses cryptographic techniques to sign DNS records, which enables clients to verify that the DNS responses they receive are authentic and have not been tampered with.

PKI is a set of technologies and processes that enable secure communication over an untrusted network, like the Internet. It uses digital certificates to provide authentication and encryption for communication. In the context of DNSSEC, PKI is used to issue digital certificates that are used to sign DNS records.

The other technologies listed in the answers are not directly related to DNSSEC. LDAP (Lightweight Directory Access Protocol) is a protocol used for accessing and maintaining distributed directory information services over an Internet Protocol (IP) network. TPM (Trusted Platform Module) is a specialized chip on a computer's motherboard that provides hardware-based security functions. TLS (Transport Layer Security) and SSL (Secure Sockets Layer) are cryptographic protocols used to provide secure communication over the Internet. However, they are not directly related to the deployment of DNSSEC.