A company has a Direct Connect link between its on-premises data center and a VPC. The VPC uses a Route 53 private hosted zone for internal AWS service names. The on-premises servers must be able to resolve names in that private hosted zone. What solution achieves this?
Choose an answer
Tap an option to check your answer.
Correct answer: Create a Route 53 inbound resolver endpoint, allow the traffic via security groups and routing, and configure the on-prem DNS servers to conditionally forward queries for the private zone to the inbound endpoint IPs..
Why this is the answer
An inbound Route 53 Resolver endpoint allows DNS queries originating from on-premises networks to resolve names in private hosted zones within AWS. By configuring on-premises DNS servers to conditionally forward queries for the specific private zone to the inbound endpoint's IP addresses, the on-premises servers can successfully resolve these internal AWS service names. Security groups and route tables must permit this traffic. An outbound resolver endpoint is used for DNS queries originating from AWS to resolve names in on-premises networks, which is the opposite of the requirement. TXT or PTR records are used for specific DNS data or reverse DNS lookups, respectively, and do not facilitate forwarding DNS queries from on-premises to AWS private hosted zones.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed