AD-DNS-06 - Zones with non-default records should be retrievable
Overviewβ
Zones with non-default records (beyond SOA and NS) are actively used for DNS resolution. Understanding which zones contain actual service records helps:
- Identify active services: Zones with records indicate active DNS services
- Assess attack surface: More active zones mean more potential targets
- Plan maintenance: Active zones require more careful change management
- Audit compliance: Verify only authorized zones are in use
Security Recommendationβ
Regularly review zones with non-default records to ensure they are all necessary and properly secured. Verify that zone contents align with authorized services and applications.
How the Test Worksβ
This test identifies DNS zones that contain records beyond the default SOA and NS records, excluding special zones like RootDNSServers and reverse lookup zones.
Related Testsβ
Test-MtAdDnsZoneCount- Counts all zones with recordsTest-MtAdDnsZonesWithOnlySoaNs- Finds zones with only default records
Test Metadataβ
| Field | Value |
|---|---|
| Test ID | AD-DNS-06 |
| Severity | Info |
| Suite | Active Directory |
| Category | AD.DNS |
| PowerShell test | Test-MtAdDnsZonesWithRecordsCount |
| Tags | AD, AD-DNS-06, AD.DNS |
Sourceβ
- Pester test:
tests/ad/dns/Test-MtAdDnsZonesWithRecordsCount.Tests.ps1 - PowerShell source:
powershell/public/ad/dns/Test-MtAdDnsZonesWithRecordsCount.ps1

