SV-259334r960735_rule
V-259334
SRG-APP-000001-DNS-000115
WDNS-22-000001
CAT II
10
Log on to the DNS server using the Domain Admin or Enterprise Admin account or Local Administrator account.
Press the Windows key + R and execute "dnsmgmt.msc".
On the opened DNS Manager snap-in from the left pane, expand the server name and then expand "Forward Lookup Zones".
From the expanded list, click to select the zone.
Once selected, right-click the name of the zone.
From the displayed context menu, click the "Properties" option.
On the opened domain's properties box, click the "General" tab.
If the "Type:" is not "Active Directory-Integrated", configure the zone for Active Directory integration.
Select "Secure only" from the "Dynamic updates:" drop-down list.
Log on to the DNS server using the Domain Admin or Enterprise Admin account or Local Administrator account.
Press the Windows key + R and execute "dnsmgmt.msc".
On the opened DNS Manager snap-in from the left pane, expand the server name and then expand "Forward Lookup Zones".
From the expanded list, click to select the zone.
Once selected, right-click the name of the zone.
From the displayed context menu, click the "Properties" option.
On the opened domain's properties box, click the "General" tab.
Verify the "Type:" is "Active Directory-Integrated".
Verify "Dynamic updates" has "Secure only" selected.
If the zone is "Active Directory-Integrated" and "Dynamic updates" are not configured for "Secure only", this is a finding.
V-259334
False
WDNS-22-000001
Log on to the DNS server using the Domain Admin or Enterprise Admin account or Local Administrator account.
Press the Windows key + R and execute "dnsmgmt.msc".
On the opened DNS Manager snap-in from the left pane, expand the server name and then expand "Forward Lookup Zones".
From the expanded list, click to select the zone.
Once selected, right-click the name of the zone.
From the displayed context menu, click the "Properties" option.
On the opened domain's properties box, click the "General" tab.
Verify the "Type:" is "Active Directory-Integrated".
Verify "Dynamic updates" has "Secure only" selected.
If the zone is "Active Directory-Integrated" and "Dynamic updates" are not configured for "Secure only", this is a finding.
M
5576