PROFESSIONAL-CLOUD-SECURITY-ENGINEER · Question #52
A customer needs to prevent attackers from hijacking their domain/IP and redirecting users to a malicious site through a man-in-the-middle attack. Which solution should this customer use?
The correct answer is C. DNS Security Extensions. DNSSEC - use a DNS registrar that supports DNSSEC, and enable it. DNSSEC digitally signs DNS communication, making it more difficult (but not impossible) for hackers to intercept and Domain Name System Security Extensions (DNSSEC) adds security to the Domain Name System (DNS)…
Question
Options
- AVPC Flow Logs
- BCloud Armor
- CDNS Security Extensions
- DCloud Identity-Aware Proxy
How the community answered
(23 responses)- A4% (1)
- C91% (21)
- D4% (1)
Explanation
DNSSEC - use a DNS registrar that supports DNSSEC, and enable it. DNSSEC digitally signs DNS communication, making it more difficult (but not impossible) for hackers to intercept and Domain Name System Security Extensions (DNSSEC) adds security to the Domain Name System (DNS) protocol by enabling DNS responses to be validated. Having a trustworthy Domain address is an increasingly important building block of today’s web-based applications. Attackers can hijack this process of domain/IP lookup and redirect users to a malicious site through DNS hijacking and man-in-the-middle attacks. DNSSEC helps mitigate the risk of such attacks by cryptographically signing DNS records. As a result, it prevents attackers from issuing fake DNS responses that may misdirect browsers to nefarious websites. https://cloud.google.com/blog/products/gcp/dnssec-now-available-in-cloud-dns
Topics
Community Discussion
No community discussion yet for this question.