SV-215647r561297_rule
V-215647
SRG-APP-000001-DNS-000115
WDNS-AC-000001
CAT II
10
Log on to the DNS server using the Domain Admin or Enterprise Admin account or Local Administrator account.
Press Windows Key + R, execute dnsmgmt.msc.
On the opened DNS Manager snap-in from the left pane, expand the server name and then expand Forward Lookup Zones.
From the expanded list, click to select the zone.
Once selected, right-click the name of the zone.
From the displayed context menu, click the “Properties” option.
On the opened domain's properties box, click the “General” tab.
If the Type: is not Active Directory-Integrated, configure the zone for AD-integration.
Select "Secure only" from the Dynamic updates: drop-down list.
Log on to the DNS server using the Domain Admin or Enterprise Admin account or Local Administrator account.
Press Windows Key + R, execute dnsmgmt.msc.
On the opened DNS Manager snap-in from the left pane, expand the server name and then expand Forward Lookup Zones.
From the expanded list, click to select the zone.
Once selected, right-click the name of the zone.
From the displayed context menu, click the “Properties” option.
On the opened domain's properties box, click the “General” tab.
Verify the Type: is Active Directory-Integrated.
Verify the Dynamic updates has "Secure only" selected.
If the zone is Active Directory-Integrated and the Dynamic updates are not configured for "Secure only", this is a finding.
V-215647
False
WDNS-AC-000001
Log on to the DNS server using the Domain Admin or Enterprise Admin account or Local Administrator account.
Press Windows Key + R, execute dnsmgmt.msc.
On the opened DNS Manager snap-in from the left pane, expand the server name and then expand Forward Lookup Zones.
From the expanded list, click to select the zone.
Once selected, right-click the name of the zone.
From the displayed context menu, click the “Properties” option.
On the opened domain's properties box, click the “General” tab.
Verify the Type: is Active Directory-Integrated.
Verify the Dynamic updates has "Secure only" selected.
If the zone is Active Directory-Integrated and the Dynamic updates are not configured for "Secure only", this is a finding.
M
4016