nerdexam
Isaca

CISA · Question #167

An organization want to use virtual desktops to deliver corporate applications to its end users. Which of the following should an IS auditor recommend to prevent domain name system (DNS) poisoning in

The correct answer is B. Configure DNS servers to create appropriately sized responses to domain resolution requests. DNS cache poisoning often exploits predictable transaction IDs and oversized or malformed DNS responses. Configuring DNS servers to generate appropriately sized responses - a reference to proper DNSSEC implementation and response rate limiting - hardens the DNS infrastructure aga

Submitted by stefanr· Apr 18, 2026Protection of Information Assets

Question

An organization want to use virtual desktops to deliver corporate applications to its end users. Which of the following should an IS auditor recommend to prevent domain name system (DNS) poisoning in their cloud environment?

Options

  • AEnable verification of administrators to protect against impersonators modifying DNS tables
  • BConfigure DNS servers to create appropriately sized responses to domain resolution requests
  • CEnsure DNS changes are propagated across all servers in the organization's cloud account
  • DProvide corporate laptops to end users will built-in antivirus tools that scan for DNS vulnerabilities

How the community answered

(38 responses)
  • A
    5% (2)
  • B
    84% (32)
  • C
    8% (3)
  • D
    3% (1)

Explanation

DNS cache poisoning often exploits predictable transaction IDs and oversized or malformed DNS responses. Configuring DNS servers to generate appropriately sized responses - a reference to proper DNSSEC implementation and response rate limiting - hardens the DNS infrastructure against poisoning by reducing the attack surface from spoofed or amplified responses. Option A addresses unauthorized admin changes, not poisoning. Option C is about DNS propagation consistency, which is unrelated to poisoning attacks. Option D (antivirus on laptops) is an endpoint control that does not protect the DNS infrastructure itself.

Topics

#DNS Security#DNS Poisoning#Cloud Security#Security Controls

Community Discussion

No community discussion yet for this question.

Full CISA Practice