A company is migrating an application from its on-premises datacenter to AWS. The application will run on Amazon EC2 instances inside a single VPC. During the three-month migration window, the EC2 instances must resolve hostnames for on-premises servers; after the migration, on-premises name resolution will no longer be required. Which approach requires the least configuration to meet these needs?
Choose an answer
Tap an option to check your answer.
Correct answer: Establish an AWS Site-to-Site VPN between the on-premises network and AWS. Deploy an Amazon Route 53 Resolver outbound endpoint in the Region that hosts the VPC..
Why this is the answer
The correct option leverages an AWS Site-to-Site VPN for secure, temporary connectivity, which is suitable for the three-month migration window. An Amazon Route 53 Resolver outbound endpoint allows EC2 instances in the VPC to forward DNS queries for on-premises hostnames to the on-premises DNS servers over the VPN, requiring minimal configuration. Incorrect options: Direct Connect with private VIF and both inbound/outbound endpoints is an overkill for a temporary migration and more expensive. Inbound endpoints are for on-premises to resolve AWS resources, which isn't the primary requirement here. Client VPN is designed for individual client access, not for VPC-wide server-to-server communication, and an inbound endpoint alone doesn't facilitate EC2 instances resolving on-premises names. Direct Connect with public VIF is for public AWS services, not private network connectivity to on-premises DNS. Using an inbound endpoint to reach on-premises DNS is misconfigured; inbound endpoints receive queries, they don't send them out to on-premises.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed