Courseiva

CEH Footprinting, Reconnaissance and Scanning Practice Question

Which THREE of the following are common countermeasures to prevent DNS zone transfers from being abused? (Choose THREE.)

⚠ Common exam trap

Many exam-takers confuse enabling recursion (Option A) with a security measure, when in fact recursion is unrelated to zone transfer control and can introduce other vulnerabilities.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Restrict zone transfers to only specific authorized secondary name servers

Option B is correct because restricting zone transfers to specific authorized secondary name servers (for example, via BIND's allow-transfer ACL) ensures that only trusted servers can request a copy of the zone, blocking unauthorized AXFR/IXFR attempts. Option C is correct because split DNS separates internal and external views, so external clients querying the public name server never see internal-only records, limiting what a leaked zone transfer could expose. Option D is correct because TSIG uses a shared secret and HMAC to cryptographically authenticate zone transfer requests, so a server will only honor an AXFR/IXFR from a peer that presents a valid signature. Option A is not a countermeasure—enabling recursion actually increases exposure to cache poisoning and amplification abuse and is unrelated to zone transfer protection. Option E is the opposite of a countermeasure, since allowing zone transfers from any host permits anyone to pull the entire zone with a single AXFR query.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable DNS recursion on the name server

    Why it's wrong here

    Enabling DNS recursion allows a name server to query other name servers on behalf of a client to resolve a query fully. While essential for many client lookups, it is entirely unrelated to the security of zone transfers, which involve the bulk transfer of DNS records. Furthermore, an open recursive resolver can be abused for DNS amplification attacks, making it a security vulnerability rather than a countermeasure.

  • ✓

    Restrict zone transfers to only specific authorized secondary name servers

    Why this is correct

    Restricting zone transfers involves configuring the primary DNS server to only permit AXFR (or IXFR) requests from a predefined list of IP addresses belonging to authorized secondary name servers. This directly prevents unauthorized external entities from performing a full enumeration of the domain's DNS records, significantly reducing the attack surface for reconnaissance. It is a fundamental security control for DNS.

  • ✓

    Implement split DNS (internal vs external views)

    Why this is correct

    Implementing split DNS involves maintaining separate DNS zone files or views for internal and external clients. External DNS servers only expose public-facing records, while internal servers contain sensitive internal hostnames and IP addresses. This architecture prevents external attackers from obtaining internal network topology information, even if they manage to perform a zone transfer from an external-facing server, as it would only contain public data.

  • ✓

    Use Transaction Signatures (TSIG) to authenticate zone transfer requests

    Why this is correct

    Transaction Signatures (TSIG) provide a cryptographic method to authenticate DNS messages, including zone transfer requests and responses, using shared secret keys. This ensures that only servers possessing the correct secret key can initiate or participate in a zone transfer, preventing unauthorized servers from obtaining zone data. TSIG also offers message integrity, protecting against tampering during the transfer process.

  • ✗

    Configure the name server to allow zone transfers from any host

    Why it's wrong here

    Configuring a name server to allow zone transfers from any host, often referred to as an "open zone transfer," is a critical security vulnerability. This setting permits any client to request and receive a full copy of the domain's DNS records, including internal hostnames, IP addresses, and other sensitive network topology information. Such a misconfiguration provides attackers with a complete blueprint of the target network, greatly aiding reconnaissance and subsequent attack phases.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

This CEH question is part of Courseiva's 913-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.