
F5Certified Technology Specialist, BIG-IP DNS
Domain 2Objective 13
Objective 2.13 Explain How to Verify That DNSSEC Is Working 302 Practice Questions (Page 3)
Part of the Section 2: Deployment domain, which makes up ~30% of our current practice bank.
18questions here
4free pages
3concepts
Questions 11–15
- 11
An admin is verifying that DNSSEC is working on a BIG-IP DNS server. They query the server for the A record of `www.example.com` and receive a response with the AA bit set and an RRSIG record. What additional check should they perform to confirm the signature is valid?
Select an answer first - 12
A BIG-IP DNS admin has generated DNSSEC key pairs and signature files for the zone example.net. The zone loads without errors, but external queries return no RRSIGs. The admin checks the file system and finds the `.key` files in `/config/dns/keys/` but the `.sig` files are missing. What is the most likely cause?
Select an answer first - 13
On a BIG-IP DNS server, where should DNSSEC signature files (e.g., .sig files) be stored so that the system can properly use them for zone signing?
Select an answer first - 14
A company has a signed zone on BIG-IP DNS. They recently rolled the ZSK (Zone Signing Key). After the rollover, external clients report validation failures. The admin queries the authoritative server directly and sees RRSIGs, but the signatures are for the old ZSK. What is the most likely cause?
Select an answer first - 15
A BIG-IP DNS admin is troubleshooting why a signed zone is not returning RRSIGs. They confirm the `.sig` files are in the correct directory and the zone loads. They query the server directly with `dig example.com SOA +dnssec` and see the AA bit set but no RRSIG. What should they check next?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by F5. “302” is a trademark of its owner, used for identification only.