GIAC
GCIH · Question #498
Which servers should be allowed to perform zone transfers from your primary DNS server?
The correct answer is B. Your secondary DNS servers. To defend against DNS-style reconnaissance, make sure you limit zone transfers. Your primary DNS server only should allow zone transfers from your secondary and tertiary DNS servers. These servers, in turn, shouldn't allow zone transfers.
Reconnaissance, Scanning, and Enumeration
Question
Which servers should be allowed to perform zone transfers from your primary DNS server?
Options
- AAll Internet clients who wish to surf to your site
- BYour secondary DNS servers
- COnly internal clients
- DAny DNS server
How the community answered
(40 responses)- B93% (37)
- C3% (1)
- D5% (2)
Explanation
To defend against DNS-style reconnaissance, make sure you limit zone transfers. Your primary DNS server only should allow zone transfers from your secondary and tertiary DNS servers. These servers, in turn, shouldn't allow zone transfers.
Topics
#DNS zone transfer#secondary DNS#DNS security#DNS hardening
Community Discussion
No community discussion yet for this question.