nerdexam
GIAC

GCIH · Question #498

Which servers should be allowed to perform zone transfers from your primary DNS server?

The correct answer is B. Your secondary DNS servers. To defend against DNS-style reconnaissance, make sure you limit zone transfers. Your primary DNS server only should allow zone transfers from your secondary and tertiary DNS servers. These servers, in turn, shouldn't allow zone transfers.

Reconnaissance, Scanning, and Enumeration

Question

Which servers should be allowed to perform zone transfers from your primary DNS server?

Options

  • AAll Internet clients who wish to surf to your site
  • BYour secondary DNS servers
  • COnly internal clients
  • DAny DNS server

How the community answered

(40 responses)
  • B
    93% (37)
  • C
    3% (1)
  • D
    5% (2)

Explanation

To defend against DNS-style reconnaissance, make sure you limit zone transfers. Your primary DNS server only should allow zone transfers from your secondary and tertiary DNS servers. These servers, in turn, shouldn't allow zone transfers.

Topics

#DNS zone transfer#secondary DNS#DNS security#DNS hardening

Community Discussion

No community discussion yet for this question.

Full GCIH Practice