nerdexam
(ISC)2

CISSP · Question #1175

Which of the following is a PRIMARY security weakness in the design of Domain Name System (DNS)?

The correct answer is B. A DNS server does not authenticate source of information. A primary security weakness in the design of Domain Name System (DNS) is that a DNS server does not authenticate the source of information it receives or sends. This makes DNS vulnerable to various attacks, such as spoofing, cache poisoning, or hijacking, where an attacker can…

Submitted by salim_om· Mar 5, 2026Communication and Network Security

Question

Which of the following is a PRIMARY security weakness in the design of Domain Name System (DNS)?

Options

  • AA DNS server can be disabled in a denial-of-service (DoS) attack.
  • BA DNS server does not authenticate source of information.
  • CEach DNS server must hold the address of the root servers.
  • DA DNS server database can be injected with falsified checksums.

How the community answered

(47 responses)
  • A
    2% (1)
  • B
    94% (44)
  • D
    4% (2)

Explanation

A primary security weakness in the design of Domain Name System (DNS) is that a DNS server does not authenticate the source of information it receives or sends. This makes DNS vulnerable to various attacks, such as spoofing, cache poisoning, or hijacking, where an attacker can impersonate a legitimate DNS server or client and send or receive false or malicious information. This can result in redirecting users to malicious websites, stealing sensitive data, or disrupting network services. A DNS server can be disabled in a denial-of-service (DoS) attack, but this is not a weakness in the design of DNS, but rather a weakness in the implementation or configuration of DNS. A DNS server must hold the address of the root servers, but this is not a weakness in the design of DNS, but rather a requirement for resolving domain names. A DNS server database can be injected with falsified checksums, but this is not a weakness in the design of DNS, but rather a weakness in the security of the DNS server database.

Topics

#DNS security#protocol vulnerabilities#source authentication

Community Discussion

No community discussion yet for this question.

Full CISSP Practice