DNS, DHCP, and Name Resolution Questions

How names and addresses are served and kept working on a network. DNS: resolution flow (stub, recursive, authoritative, root/TLD referrals), host-side resolver configuration and why one machine or process resolves differently from another, record types and their pitfalls (including apex aliasing, MX, SRV and CAA use), zones, delegation and glue, caching, TTL and negative caching, split-horizon and private zones, reverse DNS, zone transfers (AXFR/IXFR, TSIG), DNSSEC and key rollover, resolver and authoritative fleet design, forwarding versus running recursion, encrypted DNS (DoH/DoT), truncation, TCP fallback and EDNS, DNS-layer attacks (cache poisoning, amplification, spoofed-source floods), DNS health from the user's point of view, and DNS changes, mail and registrar migrations and outages. DHCP: address assignment and leases, scopes and sizing, reservations, relay across VLANs including relay agent information (option 82), redundancy and failover, and rogue or exhausted-scope failures. Includes diagnosing resolution failures that masquerade as wider outages. Excludes the layered network fault-isolation method and general packet capture, Active Directory-integrated DNS on domain controllers, DNS-based service registries for microservices, load-balancing algorithm design and global traffic steering, incident-command process and SLO or error-budget design, and generic scripting or infrastructure-as-code tooling.

MediumTechnical
70 practiced

How can an attacker get a resolver to cache a forged answer, and what makes the attack hard today? What would you still worry about?

MediumTechnical
82 practiced

Explain how DNS can be abused to flood a third party with traffic, and what you would change on authoritative and recursive servers to avoid being part of it.

HardTechnical
82 practiced

Your DNS logs show repeated zone transfer requests from many unknown addresses. How do you decide whether data left the building, what do you do right now, and what changes keep it from happening again?

MediumTechnical
76 practiced

What problem does DNSSEC solve and what does it not? Describe how a validating resolver decides an answer is genuine, and what operational risks come with turning it on.

MediumTechnical
58 practiced

A security team wants to block clients from using public encrypted DNS, while users argue it protects their privacy. How do DoH and DoT change what an enterprise can see and enforce, and what would you propose?

That is every published DNS, DHCP, and Name Resolution question for Cybersecurity Engineer so far. Browse the other topics in this category, or practice this one interactively.