A company needs to address an issue with its external DNS servers that allows an attacker to perform a full zone transfer if the IP address of a server within the BIND server's ACL configuration is spoofed. A portion of the /etc/named.conf for a BIND server is as follows: */etc/named.conf # External DNS BIND Configuration, Company LLC acl slave-servers { 10.0.0.12; //na1.compa.ny 10.0.0.13; //ns2.compa.ny zone compa.ny { type master; ile "zonefilea/compa.ny"; allow-transfer slave-servers; In which of the following ways should the BIND server implementation be modified to BEST mitigate this insecurity? OA. Change the ACL settings from IP to hostnames. OB. Establish a persistent TLS VPN between the master and slave servers. OC. Place sensors to collect the DNS transaction logs and send them to the Enterprise SIEM OD. Implement transaction signatures.

Computer Networking: A Top-Down Approach (7th Edition)
7th Edition
ISBN:9780133594140
Author:James Kurose, Keith Ross
Publisher:James Kurose, Keith Ross
Chapter1: Computer Networks And The Internet
Section: Chapter Questions
Problem R1RQ: What is the difference between a host and an end system? List several different types of end...
icon
Related questions
Question
A company needs to address an issue with its external DNS servers that allows an attacker to perform a full zone transfer if the IP address of a server within the BIND servers ACL
configuration is spoofed. A portion of the /ete/named.conf for a BIND server is as follows:
*/etc/named.conf
# External DNS BIND Configuration, Company LLC
acl slave-servers {
10.0.0.12; //na1.compa.ny
10.0.0.13; //ns2.compa.ny
zone compa.ny {
type master;
tile "zonefiles/compa.ny";
allow-tranafer I
slave-servers;
In which of the following ways should the BIND server implementation be modified to BEST mitigate this insecurity?
Change the ACL settings from IP to hostnames
O B.
Establish a persistent TLS VPN between the master and slave servers.
OC.
Place sensors to collect the DNS transaction logs and send them to the Enterprise SIEM
OD.
Implement transaction signatures.
Transcribed Image Text:A company needs to address an issue with its external DNS servers that allows an attacker to perform a full zone transfer if the IP address of a server within the BIND servers ACL configuration is spoofed. A portion of the /ete/named.conf for a BIND server is as follows: */etc/named.conf # External DNS BIND Configuration, Company LLC acl slave-servers { 10.0.0.12; //na1.compa.ny 10.0.0.13; //ns2.compa.ny zone compa.ny { type master; tile "zonefiles/compa.ny"; allow-tranafer I slave-servers; In which of the following ways should the BIND server implementation be modified to BEST mitigate this insecurity? Change the ACL settings from IP to hostnames O B. Establish a persistent TLS VPN between the master and slave servers. OC. Place sensors to collect the DNS transaction logs and send them to the Enterprise SIEM OD. Implement transaction signatures.
Expert Solution
steps

Step by step

Solved in 3 steps

Blurred answer
Recommended textbooks for you
Computer Networking: A Top-Down Approach (7th Edi…
Computer Networking: A Top-Down Approach (7th Edi…
Computer Engineering
ISBN:
9780133594140
Author:
James Kurose, Keith Ross
Publisher:
PEARSON
Computer Organization and Design MIPS Edition, Fi…
Computer Organization and Design MIPS Edition, Fi…
Computer Engineering
ISBN:
9780124077263
Author:
David A. Patterson, John L. Hennessy
Publisher:
Elsevier Science
Network+ Guide to Networks (MindTap Course List)
Network+ Guide to Networks (MindTap Course List)
Computer Engineering
ISBN:
9781337569330
Author:
Jill West, Tamara Dean, Jean Andrews
Publisher:
Cengage Learning
Concepts of Database Management
Concepts of Database Management
Computer Engineering
ISBN:
9781337093422
Author:
Joy L. Starks, Philip J. Pratt, Mary Z. Last
Publisher:
Cengage Learning
Prelude to Programming
Prelude to Programming
Computer Engineering
ISBN:
9780133750423
Author:
VENIT, Stewart
Publisher:
Pearson Education
Sc Business Data Communications and Networking, T…
Sc Business Data Communications and Networking, T…
Computer Engineering
ISBN:
9781119368830
Author:
FITZGERALD
Publisher:
WILEY