お客様のネットワークには、contoso.com という名前の Active Directory ドメイン サービス (AD DS) ドメインが含まれています。このドメインには、Server1 という名前の DNS サーバーが含まれています。Server1 は、DNSSEC によって署名された fabrikam.com という名前の DNS ゾーンをホストしています。 ドメイン内のすべてのメンバーサーバーがfabrikamに対してDNSSEC検証を実行するようにする必要があります。 com名前空間。 あなたはどうすべきでしょうか?
正解:C
The hybrid core curriculum explains that DNSSEC validation by Windows clients is controlled through the Name Resolution Policy Table (NRPT) , deployable via Group Policy. The NRPT lets administrators " require DNSSEC for specific namespaces and configure how clients validate responses." While trust anchors (Add-DnsServerTrustAnchor) are used by DNS servers performing validation, member servers acting as DNS clients rely on NRPT rules to demand DNSSEC-validated answers from their resolvers for nam ed namespaces (e.g., fabrikam.com ). The guidance emphasizes: to " enforce DNSSEC validation on domain-joined clients for a given suffix, create a GPO-based NRPT rule that requires DNSSEC ," ensuring unsigned or invalid answers are rejected. Therefore, to mak e all member servers validate DNSSEC for fabrikam.com , deploy a GPO NRPT rule targeting that namespace. Adding trust anchors on Server1 or on each member server is unnecessary (and in the latter case, inapplicable unless they run the DNS Server role).