V-259334
CAT IIThe Windows DNS Server must restrict incoming dynamic update requests to known clients.
- Ships Affected
- 1
- Total Findings
- 1
- Open
- 0
- Closed
- 1
Check Text
Log on to the DNS server using the Domain Admin or Enterprise Admin account or Local Administrator account.
Press the Windows key + R and execute "dnsmgmt.msc".
On the opened DNS Manager snap-in from the left pane, expand the server name and then expand "Forward Lookup Zones".
From the expanded list, click to select the zone.
Once selected, right-click the name of the zone.
From the displayed context menu, click the "Properties" option.
On the opened domain's properties box, click the "General" tab.
Verify the "Type:" is "Active Directory-Integrated".
Verify "Dynamic updates" has "Secure only" selected.
If the zone is "Active Directory-Integrated" and "Dynamic updates" are not configured for "Secure only", this is a finding.
Fix Text
Log on to the DNS server using the Domain Admin or Enterprise Admin account or Local Administrator account.
Press the Windows key + R and execute "dnsmgmt.msc".
On the opened DNS Manager snap-in from the left pane, expand the server name and then expand "Forward Lookup Zones".
From the expanded list, click to select the zone.
Once selected, right-click the name of the zone.
From the displayed context menu, click the "Properties" option.
On the opened domain's properties box, click the "General" tab.
If the "Type:" is not "Active Directory-Integrated", configure the zone for Active Directory integration.
Select "Secure only" from the "Dynamic updates:" drop-down list.
STIG Reference
- STIG
- Microsoft Windows Server Domain Name System (DNS) Security Technical Implementation Guide
- Version
- 2
- Release
- 4
- Rule ID
- SV-259334r960735_rule
All Occurrences
This vulnerability appears on 1 ship(s)
| Ship | Hull # | Source File | Status | Assigned To | Scan Date | Actions |
|---|---|---|---|---|---|---|
| USNS MONTFORD POINT | T-ESD-1 | _Reviewed/MONT-DC-003/Checklist/MONT-DC-003_WinServerDNS_V2R3_20251023-172313.ckl | Unassigned | 2026-01-14T12:57:38.179760 | View in Context |