AZ-800 · Question #218
SIMULATION You need to deploy a new primary DNS zone named fabrikam.com to DC1. The zone must be signed. To complete this task, sign in to the required computer or computers. Answer: Step 1: Create…
The correct answer is A. Create the zone B. Sign the zone. Both A (Create the zone) and B (Sign the zone) are correct because the task explicitly requires a signed primary DNS zone - you cannot sign a zone that doesn't exist, so both steps are mandatory and sequential. Creating the zone as an Active Directory-integrated primary zone on…
Question
Exhibit
Options
- ACreate the zone
- BSign the zone
How the community answered
(57 responses)- A100% (57)
Explanation
Both A (Create the zone) and B (Sign the zone) are correct because the task explicitly requires a signed primary DNS zone - you cannot sign a zone that doesn't exist, so both steps are mandatory and sequential. Creating the zone as an Active Directory-integrated primary zone on DC1 establishes the authoritative zone for fabrikam.com, while signing it with DNSSEC (via the Zone Signing Wizard using default settings) fulfills the "must be signed" requirement. There are no incorrect distractors here - this is a two-part simulation where omitting either step results in an incomplete solution: a zone without a signature fails the security requirement, and a signature without a zone is impossible.
Memory tip: Think of it as "Build it, then bolt it" - you always create the DNS zone first, then sign it with DNSSEC. The order is non-negotiable, just like you can't lock a door that hasn't been built yet.
Topics
Community Discussion
No community discussion yet for this question.
