Chapter 2 Flashcards

1
Q

Two primary Zones

A

File based zones and active directory - integrated DNS zones

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Primary Zone

A

Only zone type that can be edited or updated. This is bc the data in the zone is the original source of data for all domain in the zone. Updates to primary zone are mady by the DNS server that is authoritative for specific primary zone.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

AD - Integrated Zone

A

Saves zone data in the active directory database Advantages are more security and automatic replication of zone data between DNS servers.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Secondary zone

A

Read-only copy of primary zone. To configure a secondary zone, you must know the IP address of the master DNS server. Stub zone AKA secondary zone

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Stub zone

A

Special type of secondary zone in which only NS and A records of DNS servers are present. It keeps delegated zone info current, improves name resolution by enabling DNS server to preforms recursion using stub zone lists of name servers, simplifies DNS administration.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

File base zone types

A

Primary zone, secondary zone, stub zone have commonalities. All hosted on standalone server without using Active directory and zone data is stored in a local zone file.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

AXFR

A

Transfer of the complete zone. Happens only during initial configuration of a secondary DNS server.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

IXFR

A

Incremental zone transfer of zone data. Only changes on a primary DNS server are transferred to secondary DNS server.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

ForestDNSZones

A

Is a default Active Directory Partition. The msdcs zone saves its zone data by default in the ForestDNSZ one Partition. Any zone data saved in that partition is replicated to all domain controllers in the forest.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

DomainDNSZones

A

DomainDNSZones is a default Active Directory partition used to replicate zone data to all domain cotrollers in a domain.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Application Directory Partition

A

Can be used as a custom partition to save DNS data and to replicate this data only to specific domain controllers. Administrator can individually define the name of the partition, replication scope, and enlisted domain controllers.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

KSK

A

Signing key. For DNSSEC, this key validates the DNSKEY record. KSK signs the public ZSK key.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

ZSK

A

Zone signing key pair. Each zone in DNSSEC has a ZSK, which is the private portion of the key that digitally signs records in the zone.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Trust Anchors

A

Recursive or forwarding DNS server recognizes that the zone supports NSSEC if it has a DNSKEY, also called a trust anchor, for that zone. DNSKEY and KS resource records are also called trust anchors.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

msdcs zone

A

Automatically created during the installation of a DNS server. It is reserved for registering records for Microsoft domain controllers.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

GlobalNames Zone

A

Use GlobalNames zone if you plan to retire WINS or if you need single-label name resolution

17
Q

Zone transfer

A

Is the process of transferring zone data from a primary DNS server to one or more secondary DNS server. On a windows server 2016 DNS primary DNS server, zone transfer is disabled by default. Network traffic of zone transfer is not encrypted by default.

18
Q

DNS server transfer policies

A

DNS server transfer policies are a new possiblility with Windows Server 2016. With these policies, you can specify whether to deny or ignore zone transfers based on different criteria.

19
Q

Zone-level Statistics

A

Zone-level statistics give DNS server-level statistics to track sage or monitor DNS server performance.

20
Q

Scaveging

A

Scavenging is a DNS server mechanism to clean up and remove stale resource records based on time stamps..

21
Q

TLSA Record

A

TLSA DNS resource record (RR) associates a TLS server certificate association

22
Q

Unknown record support

A

As of windows server 2016, previously unknown resource recored types (such as TLSA records) are supported. Now you can add the unsupported record types into the windows DNS server zones in the binary on-wire Format.

23
Q

DNS Analytical Logging

A

DNS analytical logs are not enabled by default. They typically affect only DNS server performance at very high DNS query rates.

24
Q

To list all zones on the local DNS server

A

Use Get-DNSServerZone Powershell

25
Q

To list all info about a foward lookup zone

A

Use Get-DNSServerZone -Name pearson.com | FL *

26
Q

List all info about reverse lookup zone

A

Get-DNSServerZone -Name perason.com | FL *