PrepAway - Latest Free Exam Questions & Answers

Does this meet the goal?

Your network contains an Active Directory domain named contoso.com.
The domain contains a DNS server named Server1.
All client computers run Windows 10.
On Server1, you have the following zone configuration.

Server1 must resolve queries from all other DNS clients.
Solution: From Windows Firewall with Advanced Security on Server1, you create an inbound rule.
Does this meet the goal?

PrepAway - Latest Free Exam Questions & Answers

A.
Yes

B.
No

Explanation:

6 Comments on “Does this meet the goal?

  1. slim2018 says:

    I’m not so sure that the answer is A.

    When a DNS role is installed on a server, the appropriate Inbound Firewall is added.

    For DNS server to resolve all names that a dns client is requesting, a forwarded must be configured and recursive query enabled.

    Or am I wrong?




    1



    1
  2. briefingguy says:

    However, there is a proper way of doing this according to this article:
    https://docs.microsoft.com/en-us/windows-server/networking/dns/deploy/apply-filters-on-dns-queries

    Add-DnsServerQueryResolutionPolicy cmdlet could be used to block
    Block queries from a subnet
    Add-DnsServerClientSubnet -Name “MaliciousSubnet06” -IPv4Subnet 172.0.33.0/24 -PassThru
    Add-DnsServerQueryResolutionPolicy -Name “BlockListPolicyMalicious06” -Action IGNORE -ClientSubnet “EQ,MaliciousSubnet06” -PassThru

    Futhermore, “Exam Ref 70-743 Upgrading Your Skills to MCSA: Windows Server 2016” book covers this cmdlet in DNSServer module:

    Get-Command -Module DNSServer *policy* | Select name

    To conclude this, there is a similar question with Add-DnsServerQueryResolutionPolicy:
    https://www.briefmenow.org/microsoft/does-this-meet-the-goal-518/




    0



    0

Leave a Reply