CertaDNS

Domain Security Practitioner — assessment

questions
15
to pass
80%
retakes
Unlimited
time limit
None

Covers

  • The Estate
  • The Assessment
  • The Findings Nobody Can Fix Cleanly
  • The Plan
  • What You Are Not Doing
  • Delivering It

Sample question

An estate has eleven domains. One is DNSSEC-signed and its signatures expired some time ago; the rest are unsigned. Nobody has reported a problem. What is the finding?

  • That domain does not resolve for validating resolvers, and nobody detected it — the detection gap is the finding, above the expiry itself.Non-validating resolvers serve it happily, so internal users and most consumer ISPs see nothing. The people who cannot reach it are disproportionately at organisations that validate, which is to say business customers.
  • The other ten domains should be signed to match.The estate has just demonstrated it cannot operate the one signed zone it has. Adding ten more adds ten more silent outage modes.
  • Nothing urgent — an expired signature degrades protection rather than availability.A validating resolver returns SERVFAIL. The domain does not resolve at all for that population.
  • The DS record should be removed permanently to prevent recurrence.Removing it is a legitimate emergency measure to end the outage. Making it permanent is a decision that belongs on the not-doing list with its reasoning and a revisit trigger.

Every option carries an explanation, including the wrong ones.

The assessment needs an account.

Passing issues Domain Security Practitioner. A CertaDNS Academy certificate records that you completed a course and passed its assessment on a given date. It is not a professional certification, it is not accredited, and it does not expire.