
F5Certified Technology Specialist, BIG-IP DNS
Domain 2Objective 13
Objective 2.13 Explain How to Verify That DNSSEC Is Working 302 Practice Questions (Page 4)
Part of the Section 2: Deployment domain, which makes up ~30% of our current practice bank.
18questions here
4free pages
3concepts
Questions 16–18
- 16
A BIG-IP DNS admin has placed DNSSEC signature files for the zone example.org in `/config/dns/keys/`. The zone loads, but queries return no RRSIGs. What should the admin do to fix this?
Select an answer first - 17
A BIG-IP DNS admin has a signed zone that was working. After a system update, the zone loads but returns no RRSIGs. The admin checks the zone directory and finds the `.sig` files are present but have the wrong ownership. What is the most likely cause?
Select an answer first - 18
An admin is verifying DNSSEC on a BIG-IP DNS server that is authoritative for a signed zone. They query the server directly and receive a response with the AA bit set and an RRSIG. However, when they query the same zone through a recursive resolver, the response has the AD bit set but no RRSIG. What does this indicate?
Select an answer first
Finished these 3 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to 302
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by F5. “302” is a trademark of its owner, used for identification only.