🔥 40% Off Crucial Exams Memberships — Deal ends today!

3 hours, 1 minute remaining!

GCP Professional Cloud Security Engineer Practice Question

Your company hosts the public DNS zone "contoso.com" in Cloud DNS. Security requires DNSSEC to protect against cache-poisoning attacks. You change the zone's dnssec_state from "off" to "on" using Terraform and select the RSASHA256 key algorithm. The apply completes and a key-signing key now appears in the Cloud DNS console, yet public resolvers still mark the zone as "insecure." What action must you take to finish the DNSSEC rollout?

  • Submit the DS record provided by Cloud DNS to the domain registrar so the .com parent zone publishes it.

  • Manually add DNSKEY and RRSIG records to the zone file so validators can see the signatures.

  • Create an asymmetric key in Cloud KMS and upload its public portion to Cloud DNS as an external KSK.

  • Enable DNSSEC validation on every internal and external recursive resolver that queries the zone.

GCP Professional Cloud Security Engineer
Securing communications and establishing boundary protection
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot