Amazon Web Services AWS Certified Security - Specialty SCS-C02 Question # 110 Topic 12 Discussion

Amazon Web Services AWS Certified Security - Specialty SCS-C02 Question # 110 Topic 12 Discussion

SCS-C02 Exam Topic 12 Question 110 Discussion:
Question #: 110
Topic #: 12

A company needs to implement DNS Security Extensions (DNSSEC) for a specific subdomain. The subdomain is already registered with Amazon Route 53. A security engineer has enabled DNSSEC signing and has created a key-signing key (KSK). When the security engineer tries to test the configuration, the security engineer receives an error for a broken trust chain.

What should the security engineer do to resolve this error?


A.

Replace the KSK with a zone-signing key (ZSK).


B.

Deactivate and then activate the KSK.


C.

Create a Delegation Signer (DS) record in the parent hosted zone.


D.

Create a Delegation Signer (DS) record in the subdomain.


Get Premium SCS-C02 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.