Master the CompTIA Network+ Exam. Prepare with flashcards and multiple choice questions, each question has hints and explanations. Get ready for your certification!

Each practice test/flash card set has 50 randomly selected questions from a bank of over 500. You'll get a new set of questions each time!

Practice this question and more.


Which DNS response enhancement requires additional configurations on the DNS server?

  1. DNS over TLS (DoT)

  2. Domain Name Security Extensions (DNSSEC)

  3. SPF Protocol

  4. AAAA records

The correct answer is: Domain Name Security Extensions (DNSSEC)

Domain Name Security Extensions, or DNSSEC, is a critical enhancement to DNS that requires additional configuration on the DNS server to function properly. DNSSEC adds a layer of security to the standard DNS protocol by ensuring that the responses received from the DNS are authentic and have not been tampered with. This is achieved through the use of digital signatures and cryptographic keys, which necessitate configuring the DNS infrastructure to support these features. Setting up DNSSEC involves creating cryptographic keys, signing DNS zones with these keys, and ensuring that the DNS records include the necessary DNSSEC data such as RRSIG (Resource Record Signature) and DS (Delegation Signer) records. Each DNS server in the hierarchy must also be properly configured to validate DNSSEC signatures, which involves adding support for these enhancements to all relevant DNS servers. Other options, while related to DNS functionality and enhancements, generally do not require such extensive configuration. For instance, DNS over TLS (DoT) is a security protocol for encrypting DNS queries but may not necessarily require as much configuration for basic implementation when compared to the full signing process of DNSSEC. The SPF (Sender Policy Framework) protocol, while important for email validation, is more related to email authentication than DNS itself. AAAA