🔥 40% Off Crucial Exams Memberships — Deal ends today!

1 hour, 54 minutes remaining!

Certified Ethical Hacker (CEH) Practice Question

During an external penetration test, you issue the command "dig axfr example.com @ns1.example.com" and the full zone file is returned, exposing internal hostnames and network ranges. The client wants a fast footprinting countermeasure that will block this information disclosure while leaving normal public name resolution unaffected. Which single change should you recommend?

  • Disable recursive resolution on all internal workstation DNS resolvers

  • Enable DNSSEC signing for the public zone

  • Publish an SPF TXT record listing authorized outbound mail servers

  • Restrict AXFR so that zone transfers are permitted only to the organization's designated secondary DNS server IP addresses

Certified Ethical Hacker (CEH)
Reconnaissance Techniques
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot