Question 1
Q1A financial enterprise is migrating its global application delivery infrastructure to F5 BIG-IP DNS. The architecture team needs to understand how DNS queries will flow from end users to the BIG-IP DNS listeners to ensure proper security and routing configurations.
The enterprise currently uses a mix of internal caching resolvers and external public DNS services. The security team has mandated that BIG-IP DNS must not perform recursive lookups for external domains to prevent potential DNS amplification attacks.
In a standard DNS query dataflow where a client queries a public domain hosted on the BIG-IP DNS, how does the BIG-IP DNS handle the resolution process, and what is the primary difference between iterative and recursive queries in this context?
Show answer & explanation
Correct answer: B
In a standard DNS flow, the client asks its Local DNS (LDNS) to resolve a name recursively. The LDNS then performs iterative queries to the Root, TLD, and eventually the authoritative nameserver (the BIG-IP DNS). The BIG-IP DNS answers the iterative query authoritatively. It does not perform recursion for the client unless explicitly configured as a caching resolver.