SSCP Network and Communications Security Practice Question
Which transport layer protocol is used by DNS for its queries and responses, and why is it appropriate?
⚠ Common exam trap
SSCP often tests the misconception that DNS uses TCP for reliability; candidates pick TCP because they associate reliability with critical services, but DNS is designed around UDP's speed with application-level retry logic.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
UDP, because it is connectionless and fast, suitable for short exchanges.
DNS primarily uses UDP on port 53 because queries and responses are typically small, single-packet exchanges where the low overhead and lack of connection setup make UDP fast and efficient. TCP is used only for large responses (e.g., zone transfers or DNSSEC) or when truncation occurs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
UDP, because it guarantees packet ordering.
Why it's wrong here
UDP is connectionless and provides no ordering, acknowledgement, or retransmission guarantees; ordering is a TCP feature. The option tempts because UDP genuinely is the transport DNS uses, but the stated justification is false — DNS tolerates reordering and relies on application-layer retries rather than transport-level sequencing.
- ✗
TCP, because it provides error checking and retransmission.
Why it's wrong here
DNS uses UDP for ordinary queries; TCP's error checking and retransmission are not why the protocol was chosen, and TCP is only used for zone transfers and large responses. The distractor tempts by pairing a real TCP feature with the wrong protocol, since UDP already carries DNS's typical query traffic.
- ✗
TCP, because reliability is critical for DNS resolution.
Why it's wrong here
DNS queries and responses use UDP port 53 for standard resolution; TCP is reserved for zone transfers, responses exceeding 512 bytes, and DNSSEC. TCP's handshake and retransmission add latency that would burden every routine lookup, so reliability is not the criterion — UDP's low overhead is what suits the query-response model.
- ✓
UDP, because it is connectionless and fast, suitable for short exchanges.
Why this is correct
DNS queries and responses use UDP port 53, whose connectionless datagram model avoids handshake overhead and suits the short request-response exchanges typical of name resolution. This satisfies the requirement for a fast transport matching DNS's small, self-contained message pattern.
About these practice questions
Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.