- Home
- Interview Questions
- DNS and Active Directory
A negative cache TTLis used when an authoritative server responds to a query indicating that the record queried doesn’t exist and indicates the amount of time that this negative answer may be held. Negative caching is quite helpful in preventing repeated queries for names that don’t exist.
The primary zone is responsible for maintaining all the records for the DNS zone. It contains the primary copy of the DNS database. All record updates occur on the primary zone.
You will want to create and add primary zones whenever you create a new DNS domain.
There are two types of primary zone:
--> Primary zone
--> Primary zone with Active Directory integration (Active Directory DNS)
The advantages are :
- An Active Directory–integrated zone can use secure dynamic updates.
- The dynamic DNS standard allows secure-only updates or dynamic updates, not both.
- If you choose secure updates, then only machines with accounts in Active Directory can register with DNS. Before DNS registers any account in its database, it checks Active Directory to make sure it is an authorized domain computer.
- An Active Directory–integrated zone stores and replicates its database through Active Directory replication. Because of this, the data gets encrypted as it is sent from one DNS server to another.
The main disadvantage of Active Directory integrated DNS is that it has to reside on a domain controller because the DNS database is stored in Active Directory.So we cannot load this zone type on a member server, and small organizations might not have the resources to set up a dedicated domain controller.
One or more well-connected (highly reliable and fast) TCP/IP subnets.
A site allows administrators to configure Active Directory access and replication topology to take advantage of the physical network.
A Site object in Active Directory represents a physical geographic location that hosts networks. Sites contain objects called Subnets.
Sites can be used to Assign Group Policy Objects, facilitate the discovery of resources, manage active directory replication, and manage network link traffic.