Question

In: Computer Science

What is DNS cache locking, and what does it prevent? How does a system administrator enable...

  1. What is DNS cache locking, and what does it prevent?

  1. How does a system administrator enable scavenging?

  1. How are a stub zone records updated if the stub zone is Active Directory integrated?

  1. What does the Windows Server 2016 feature "DNS Policy" allow an administrator to manage?

  1. How does DNSSEC use zone signing to help secure zones?

Solutions

Expert Solution

DNS cache locking:-

To mitigate the risks in windows Server 2016 you can use DNS cache Locking to determine when information in the DNS resolver cache can be overwritten. when you enable cache locking,The DNS server doesn't allow updates to cached records until the TTL is expired...!

cache locking is a windows server 2016 feature that allows you to control securely,when information in the DNS resolver cache can be overwritten. when recursive DNS server responds to a query, it catches the result,to respond quickly to another query which is requesting same information.

this feature protects / prevents DNS cache records from DNS cache poisoning attacks caused  by malicious users.and it's configured in percentanges....!!!

DNS Scavenging:-

it's a process of removing outdated DNS records, by looking at timestamps it will remove the DNS records. DNS Scavenging is not configured default and these records will removed in 14 days.Scavenging can be set in 3 areas 1) Individual Record ,2)Zone and 3) Server.

Scavenging on Zone:- Click on Server Manager > Tools > DNS > Right Click on Zone you want > click on properties > check the scavenge stale resource records.

Scavenging on DNS Server:- Server manager > tools > dns > right click on dns server >click on properties > enable automatic scavenging of state records. and by typing dnscmd.exe you can verify the scavenging....!

Stub Zone:- it's a copy of DNS zone which contains only a resource records which csn identify the dns servers for that zone. and we can add forward or reverse lookup zone. and we can add an active directory-integrated zone too.it contains SOA and NS records(Start of authority and name server. The ip address of one or more master servers can be used to update the stub zone.

DNS policy can be used to control the dns server processes name resolution queries based on policies you defined..admin can use this to allow primary and secondary dns servers to respond to client queries which is dns client queries based on their location of the client and the resource of which the client is trying to connect. and can manage the dns responses based on the time of day and by applying filters on dns queries. we can use dns policy like forensic like, we can redirect hacker or any malicious users or dns clients to a non existing ip address.

DNSSEC (the domain name system security extensions) can protect the internet from forged dns data by using digital signature, and public key cryptography to validate it at it's destination and arriving at the zone. Here.Each zone will have a pair of private and public keys. and this zone's public key is published by using dns, while other side, the private key of zone's is kept safe and that could be stored offline. A zone's private key signs individual dns data in that specific zone, creating digital signtaures which are also published with dns..


Related Solutions

What is a DNS cache poisoning attack, and how does it affect a network client? How...
What is a DNS cache poisoning attack, and how does it affect a network client? How does the Response Rate Limiting role feature mitigate a DNS amplification attack? What are the two keys that must be generated if you want to secure a zone with a digital signature? What is the purpose of each? What is DNS delegated administration, why might you want to use it, and how do you configure it? How are trust anchors distributed?
The Domain Name System (DNS) is used in what capacity and how does it work?
The Domain Name System (DNS) is used in what capacity and how does it work?
How does DNS balance load across a system replica servers?
How does DNS balance load across a system replica servers?
Network security question: what is dns? how does it work? identify the attack surface of dns....
Network security question: what is dns? how does it work? identify the attack surface of dns. clearly detail how the exploitable services of dns can be attacked
What is a primer and how does it enable PCR?
What is a primer and how does it enable PCR?
Q1/ A- What is cache memory and how it works? B- What are the three cache...
Q1/ A- What is cache memory and how it works? B- What are the three cache mapping approaches and what is the pros and cons of each approach? C- What is the cache replacement policies and read/write policies?
What are the main components of a balance sheet and how does it enable managers to...
What are the main components of a balance sheet and how does it enable managers to make estimates of new items for inclusion in the budget? What are some of the reasons that cause a business to experience poor cash flow? What are the advantages of monitoring expenditure? Why do organizations need a good financial record keeping system? Name and give a brief description of 3 accounting software that an organization can use. Describe the following terms: a. Gross profit...
What is DNS and what is it used for? How is it structured? What are the...
What is DNS and what is it used for? How is it structured? What are the implications of this structure? Describe an example DNS query.
What is Carcinoma? How does it form? What can prevent it? What are the symptoms of...
What is Carcinoma? How does it form? What can prevent it? What are the symptoms of it?
What is Melanoma? How does it form? What can prevent it? What are the symptoms of...
What is Melanoma? How does it form? What can prevent it? What are the symptoms of it?
ADVERTISEMENT
ADVERTISEMENT
ADVERTISEMENT