Google
PROFESSIONAL-CLOUD-NETWORK-ENGINEER · Question #5
You are disabling DNSSEC for one of your Cloud DNS-managed zones. You removed the DS records from your zone file, waited for them to expire from the cache, and disabled DNSSEC for the zone. You…
The correct answer is C. Disable DNSSEC at your domain registar. Before disabling DNSSEC for a managed zone you want to use, you must deactivate DNSSEC at your domain registrar to ensure that DNSSEC-validating resolvers can still resolve names in the https://cloud.google.com/dns/docs/dnssec-config
Submitted by amina.ke· Apr 18, 2026Configuring network services
Question
You are disabling DNSSEC for one of your Cloud DNS-managed zones. You removed the DS records from your zone file, waited for them to expire from the cache, and disabled DNSSEC for the zone. You receive reports that DNSSEC validating resolves are unable to resolve names in your zone. What should you do?
Options
- AUpdate the TTL for the zone.
- BSet the zone to the TRANSFER state.
- CDisable DNSSEC at your domain registar.
- DTransfer ownership of the domain to a new registar.
How the community answered
(32 responses)- A3% (1)
- B16% (5)
- C72% (23)
- D9% (3)
Explanation
Before disabling DNSSEC for a managed zone you want to use, you must deactivate DNSSEC at your domain registrar to ensure that DNSSEC-validating resolvers can still resolve names in the https://cloud.google.com/dns/docs/dnssec-config
Topics
#DNSSEC#Cloud DNS#Domain Registrar#DNS Resolution
Community Discussion
No community discussion yet for this question.