Basic DNS Security

Post ported from old site.
Basic DNS(BIND9) Security -- and I do mean basic -- comes in the form of two simple options placed in your named.conf options {...} section.  The first is to turn off recursion and the second is to hide the bind version.
Why do we want to do these things?