DNSSEC
Domain Name System Security Extensions
Adds cryptographic signatures to DNS to prevent spoofing and cache poisoning.
Domain Name System Security Extensions add cryptographic signatures to DNS records so resolvers can verify that a response is authentic and unaltered, which defeats cache poisoning and spoofing. Trust flows in a chain from the signed root zone down to each domain. DNSSEC authenticates records but does not encrypt the query itself, which is the job of DNS over HTTPS or DNS over TLS.
Related terms
Looking DNSSEC up is step one. Getting tested on it is step two.
A free account opens all 4 Domain 1 objectives, 271 exam-style questions with a lesson and a lab on each, a placement check that skips what you already know, and a dated plan. No card.
Not affiliated with or endorsed by CompTIA.
