Certified Ethical Hacker (CEH) Practice Question

During a security audit you confirm that external users can run an unrestricted "dig axfr" against the company's Internet-facing DNS server and obtain a full list of host records. To implement an effective footprinting countermeasure while keeping normal name resolution intact, which change should you make on the authoritative server?

  • Disable recursive queries on the authoritative name server.

  • Replace A records with CNAME aliases and move DNS service to TCP port 8053.

  • Enable DNSSEC signing for the public zone to authenticate responses.

  • Permit zone transfers solely to trusted secondary DNS servers using an IP ACL or TSIG authentication.

Certified Ethical Hacker (CEH)
Reconnaissance Techniques
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot