A company manages resources across VPCs in multiple AWS Regions and needs to use an internal domain suffix aws.example.com for those resources. What must the network engineer do to apply the aws.example.com DNS suffix across all resources?
Choose an answer
Tap an option to check your answer.
Correct answer: Create one Amazon Route 53 private hosted zone for aws.example.com. Associate the private hosted zone with every VPC that has resources. In the private hosted zone, create DNS records for all resources..
Why this is the answer
The correct approach is to create a single Route 53 private hosted zone for aws.example.com and associate it with all relevant VPCs across different Regions. This allows all resources within those associated VPCs to resolve DNS queries for aws.example.com using the records defined in that single hosted zone. This centralizes DNS management. Option 1 is incorrect because creating a separate private hosted zone in each Region for the same domain suffix is inefficient and complicates management. Each zone would need to be updated independently. Option 2 is incorrect because Route 53 private hosted zones do not support zone transfers with VPCs in the traditional DNS sense. Association is the mechanism for VPCs to query the zone. Option 3 is incorrect because creating a hosted zone for example.com and using a single record with a multivalue routing policy for aws.example.com is not the standard or most scalable way to manage a subdomain across multiple resources and VPCs. A dedicated private hosted zone for aws.example.com is more appropriate.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed