AD-DNS-07 - Zone record count details should be retrievable
Overviewβ
Detailed record distribution across zones helps identify:
- High-traffic zones: Zones with many records may be critical infrastructure
- Underutilized zones: Zones with few records may be candidates for consolidation
- Potential issues: Unusual record distributions may indicate problems
- Resource planning: Understanding record counts helps capacity planning
Security Recommendationβ
Review zones with unusually high record counts for:
- Stale or orphaned records that should be removed
- Unauthorized records that may indicate compromise
- Configuration errors causing excessive record creation
How the Test Worksβ
This test provides a detailed breakdown of record counts per zone, including the most common record types in each zone.
Related Testsβ
Test-MtAdDnsZoneCount- Counts zones with recordsTest-MtAdDnsDynamicRecordCount- Analyzes dynamic vs static records
Test Metadataβ
| Field | Value |
|---|---|
| Test ID | AD-DNS-07 |
| Severity | Info |
| Suite | Active Directory |
| Category | AD.DNS |
| PowerShell test | Test-MtAdDnsZoneRecordDetails |
| Tags | AD, AD-DNS-07, AD.DNS |
Sourceβ
- Pester test:
tests/ad/dns/Test-MtAdDnsZoneRecordDetails.Tests.ps1 - PowerShell source:
powershell/public/ad/dns/Test-MtAdDnsZoneRecordDetails.ps1

