CompTIA Linux+ (XK0-006)TroubleshootingMedium
A system administrator is investigating intermittent application timeouts on a server. They suspect that DNS resolution might be slow or failing. To test DNS resolution for a specific domain (`example.com`) using a particular DNS server (`192.168.1.1`), which command provides the most direct and specific test?
- A`dig @192.168.1.1 example.com`
- B`ping example.com`
- C`nslookup example.com`
- D`host example.com 192.168.1.1`
Show answer & explanationAnswer & explanation
Correct answer: A. `dig @192.168.1.1 example.com`
The `dig` command is the most powerful and flexible tool for querying DNS servers. The syntax `dig @<DNS_SERVER_IP> <DOMAIN>` allows direct querying of a specified DNS server for a given domain, bypassing any local resolver configurations and providing detailed DNS response information.
Why the other options are wrong
- B. `ping` tests reachability, but relies on the system's configured DNS resolver and provides no DNS-specific diagnostic output.
- C. `nslookup example.com` uses the system's configured DNS resolvers and can be used to query a specific server if specified, but `dig` is considered more advanced and feature-rich for detailed troubleshooting.
- D. `host example.com 192.168.1.1` is a valid way to query a specific DNS server, but `dig` provides more detailed and raw DNS response information, making it generally preferred for troubleshooting.
dig for Specific DNS Server Query
The `dig` (domain information groper) command is a flexible tool for querying DNS name servers, allowing users to specify a particular DNS server to test resolution for a given domain.
- Syntax: `dig @<DNS_SERVER_IP> <DOMAIN> [QUERY_TYPE]`.
- Provides detailed DNS response, including authoritative server, query time, and answer section.
- Useful for diagnosing problems with specific DNS servers or verifying DNS records.
Memory trick: To 'Dig' into a specific DNS server, use '@' and the domain.