A company has multiple VPCs including a shared-services VPC and several application VPCs. All VPCs already have connectivity to on-premises DNS servers. Applications in the application VPCs must resolve on-premises internal domains, local VPC names, and domains hosted in Route 53 private hosted zones. What should a network engineer implement to meet these requirements?
Choose an answer
Tap an option to check your answer.
Correct answer: Create a new Route 53 Resolver outbound endpoint in the shared services VPC. Create forwarding rules for the on-premises domains. Associate the rules with the new Resolver endpoint and each application VPC..
Why this is the answer
The correct solution uses a Route 53 Resolver outbound endpoint because the application VPCs need to query on-premises DNS servers for internal domains. An outbound endpoint allows DNS queries originating from AWS to be forwarded to external DNS servers. Creating forwarding rules for the on-premises domains and associating them with the outbound endpoint and the application VPCs ensures that these specific queries are directed to the on-premises DNS. This setup also inherently allows resolution of local VPC names and Route 53 private hosted zones, as these are handled by the default VPC DNS resolver. The incorrect options involving an inbound endpoint are wrong because an inbound endpoint allows on-premises resources to query AWS DNS, not the other way around. Updating DHCP options to point to a new Resolver endpoint is unnecessary and potentially disruptive, as the default VPC DNS resolver (which Route 53 Resolver enhances) already handles AWS-internal resolution.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed