
F5Certified Technology Specialist, BIG-IP DNS
Domain 2Objective 13
Objective 2.13 Explain How to Verify That DNSSEC Is Working 302 Practice Questions (Page 2)
Part of the Section 2: Deployment domain, which makes up ~30% of our current practice bank.
18questions here
4free pages
3concepts
Questions 6–10
- 6
A BIG-IP administrator needs to verify that DNSSEC signature files are in the correct location. Which command would list the .sig files in the proper directory?
Select an answer first - 7
A technician is troubleshooting DNSSEC and wants to verify that a specific A record in a zone is signed. Which command-line tool and query type would directly show the RRSIG record associated with that A record?
Select an answer first - 8
When verifying DNSSEC responses from a BIG-IP DNS server, which flag in the response header indicates that the server is authoritative for the zone and therefore its DNSSEC signatures should be trusted?
Select an answer first - 9
A DNS administrator wants to confirm that a zone's records are actually signed with DNSSEC. Which type of DNS record should the administrator look for in the zone's data to verify that signing is active?
Select an answer first - 10
A company has just configured DNSSEC signing on their BIG-IP DNS authoritative zone for example.com. A junior admin wants to confirm that the zone is actually being served with signatures. They run a query for the SOA record of example.com from an external resolver and see no RRSIG in the response. What is the most likely reason the RRSIG is missing?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by F5. “302” is a trademark of its owner, used for identification only.