Courseiva
Configuring Network ServicesmediumMultiple ChoiceObjective-mapped

PCNE Configuring Network Services Practice Question

To enable DNSSEC for a Cloud DNS managed zone, what must be configured?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Set the DNSSEC state to 'on' for the zone

DNSSEC is enabled at the zone level by setting the DNSSEC state to 'on'. This can be done via the console or gcloud with '--dnssec-state=on'.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Create a response policy

    Why it's wrong here

    Response policies are for DNS overrides, not DNSSEC.

  • Set the DNSSEC state to 'on' for the zone

    Why this is correct

    This is the primary step to enable DNSSEC.

  • Add DS records to the parent zone

    Why it's wrong here

    DS records in parent zone are needed for chain of trust, but DNSSEC must first be enabled on the zone itself.

  • Set the zone type to private

    Why it's wrong here

    Private zones can also have DNSSEC, but that's not required.

About these practice questions

Courseiva writes every PCNE question from scratch — 961 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCNE practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNE exam.