クラウドホスト型小売アプリケーションに対する偵察フェーズをシミュレーションしながら、チームはインフラストラクチャをマッピングするためにDNSレコードを収集しようとします。サブドメインへのブルートフォース攻撃は避け、ドメインのメールサーバー、権威ネームサーバー、シリアル番号や更新間隔といった潜在的な管理情報といった具体的な詳細情報の収集を目指します。
これらの目標を考慮すると、ターゲット ゾーンに関する管理メタデータと技術メタデータの両方を抽出するには、どの DNS レコード タイプをクエリする必要がありますか?
正解:B
The correct choice is the SOA record because it uniquely provides authoritative administrative and operational metadata about a DNS zone. In CEH reconnaissance techniques, DNS enumeration is a high-value passive and semi-passive method to learn about an organization's infrastructure without actively attacking hosts. The Start of Authority record defines core parameters of the zone and identifies the primary authoritative name server for that domain. Most importantly for this question, the SOA record contains fields that directly match "serial number and refresh interval," which are classic SOA elements used for zone replication and synchronization behavior between primary and secondary DNS servers.
An SOA record typically includes the primary name server, the responsible party field often formatted like an email address for the zone administrator, the zone serial number, and timing values such as refresh, retry, expire, and minimum TTL. These details can reveal change frequency, operational practices, and sometimes administrative contact clues, all of which are relevant in reconnaissance and reporting.
The other record types do not meet the requirement. MX records identify mail exchangers for the domain but do not include serial or refresh parameters. NS records list authoritative name servers but lack administrative timing metadata. TXT records store arbitrary text such as SPF, DKIM, DMARC, or verification strings and are useful for email security posture analysis, but they do not provide the zone control fields the question references. Since the question explicitly calls out serial and refresh interval, the SOA record is the only option that fits completely.