To prevent someone poisoning DNS records, DNSSEC was introduced to protect the DNS traffic. Each DNS Record is digitally signed, creating an RRSIG record to protect against attacks assuring you that they are valid and their integrity has been maintained.
Exam tip:
DNSSEC produces a RRSIG record for each host.
DNSSEC produces a RRSIG record for each host.