DNS Security and DANE Lecture Review

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/13

flashcard set

Earn XP

Description and Tags

Flashcards covering DNS security threats such as on path attacks, spoofing, cache poisoning, and amplification, along with defenses like DNSSEC, DNS socket pooling, DNS cache locking, response rate limiting, and DANE.

Last updated 1:54 AM on 9/21/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

14 Terms

1
New cards

What occurs during an on path or man in the middle attack in DNS communication?

An attacker intercepts communication, steals data, manipulates network traffic, and can impersonate devices in spoofing to send clients to fake websites and servers.

2
New cards

How does domain name system security extensions or DNSSEC protect DNS record data?

The recursive DNS server digitally signs the record so the client knows it is from the authentic server and was not changed in transit.

3
New cards

What happens under DNSSEC if a DNS record is not signed by the authentic server or is altered in transit?

The client will not use the record because the missing or altered digital signature shows that the data was changed or is unauthentic.

4
New cards

How does an attacker execute a DNS cache poisoning attack?

The attacker impersonates the authoritative server and repeatedly sends fake records to get the recursive DNS server to accept and store a fake record in its cache for the TTL duration.

5
New cards

Why did traditional DNS query traffic make cache poisoning attacks easier?

Traditionally, all DNS query traffic originated from virtual port 53, making it an easy target for an attacker.

6
New cards

What is DNS socket pooling and how many ports does it use?

It is a defense where the recursive DNS server randomly uses a group of 2,500 or more ports to query an authoritative server.

7
New cards

How does DNS cache locking defend against cache poisoning?

It forces the DNS server to use cached records for their full TTL and prevents records from being overwritten before the TTL has expired.

8
New cards

What strategy combining TTL and DNS cache locking helps combat cache poisoning?

A shortened TTL combined with cache locking ensures that even if the cache becomes poisoned, the false record will be overwritten sooner.

9
New cards

How does a DNS amplification denial of service (DoS) attack work?

An attacker impersonates a DNS client and sends thousands of DNS requests so that the DNS server floods the actual client with responses, reducing its bandwidth or causing it to freeze or crash.

10
New cards

How does response rate limiting mitigate a DNS amplification attack?

It stops or limits the DNS server from replying to a client that has sent too many queries in a certain amount of time.

11
New cards

What record does a DAN configured DNS server return in addition to an A or Quad A record?

A transport layer security authentication or TLSA record.

12
New cards

What is the function of a transport layer security authentication or TLSA record in DANE?

It tells the client which digital signature to look for from the legitimate server so the client can verify it before connecting.

13
New cards

What prerequisite is required for DNS based authentication of named entities or DAN to function?

DNSSEC must also be configured on the DNS server.

14
New cards

What is the main practical application of DANE mentioned in the lecture?

It is mainly used to authenticate email servers and fight spam, but can also be used for websites and other servers.