Certified Ethical Hacker CEH · Free Practice Question Medium

Question 87

Which of the following is the best control against DNS Cache poisoning?
  • A A. Implement intrusion detection systems (IDS).
  • B B. implement Domain Name System Security Extensions (DNSSEC)
  • C C. Implement biometric authentication.
  • D D. Implement virtual private networks (VPNs).
Reveal correct answer

Correct answer: B

Explanation

Correct Answer: B. Implement Domain Name System Security Extensions (DNSSEC) Explanation: The best control against DNS Cache poisoning is to implement Domain Name System Security Extensions (DNSSEC). DNSSEC is a set of DNS protocol extensions that add security mechanisms to DNS resolvers and DNS zones to prevent DNS cache poisoning attacks. DNSSEC ensures the authenticity and integrity of DNS data by digitally signing DNS records. This allows DNS resolvers to verify that the information they receive is valid and hasn't been tampered with, making it more difficult for attackers to inject fake DNS responses into the resolver's cache. While implementing intrusion detection systems (IDS), biometric authentication, and virtual private networks (VPNs) can help to improve overall security, they are not specifically designed to prevent DNS cache poisoning attacks. DNSSEC is the best control for addressing this specific threat.

Discussion

Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.

You must be logged in to post a comment.

Preparing For

Your Certification?

255+ certifications
Detailed explanations
Free PDF samples

Has All The Questions You Need