Memory hook: Name to address; address to network.
Must remember
- AD-integrated DNS stores supported zones in the directory and replicates through AD. Forward lookup maps names to addresses; reverse lookup maps addresses to names; SRV records help clients locate directory services.
- Forwarders send unresolved queries to another resolver; conditional forwarders target specific namespaces. Hybrid Azure/on-premises DNS needs deliberate paths in both directions and must avoid loops.
- DNS policies control supported responses/handling by criteria. DNSSEC validates signed DNS data; it does not encrypt DNS traffic or solve every name-resolution problem.
- DHCP scopes define address pools and options; exclusions reserve addresses outside allocation; reservations bind a specific client to an address. Relay is required when broadcasts cannot reach the server across routed networks.
- Configure DHCP failover/high availability using supported modes and partner behavior. Exhausted scopes, wrong options, stale leases and duplicate addresses require different remedies.
- Troubleshoot client IP, mask, gateway, DNS servers, route and firewall in order. A successful ping to an IP does not establish that DNS, domain discovery or the required application port works.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Only a partner DNS namespace needs another resolver | A conditional forwarder for that namespace. |
| Clients on another subnet receive no lease | Check relay, routing, scope availability and server authorization/configuration. |
Traps
- DNSSEC provides authenticity/integrity, not confidentiality.
- A DHCP reservation is not the same as manually configuring a static address outside DHCP.
Active recall
1. Which DNS records help locate domain controllers?
SRV records for the relevant directory services.
2. Why can hybrid DNS loop?
Forwarders can send unresolved queries back to each other without a proper authority path.
3. What should DHCP options provide?
Appropriate network settings such as gateway and DNS servers for the scope.
4. How diagnose scope exhaustion?
Inspect available addresses, leases, exclusions and unexpected client demand.
5. Why verify time during domain issues?
Authentication may fail even when addressing and name resolution are correct.