A company requires all internal application connectivity to use private IP addresses. The solutions architect created interface VPC endpoints to connect to AWS public services, but DNS names are resolving to public IP addresses and internal services cannot reach the interface endpoints. What should the solutions architect do to fix this?
Choose an answer
Tap an option to check your answer.
Correct answer: Enable the Private DNS option for the VPC endpoint..
Why this is the answer
Enabling the Private DNS option for the VPC endpoint ensures that when applications within your VPC query the DNS name for the AWS service, it resolves to the private IP addresses of the interface endpoint, rather than the public IP addresses. This allows internal services to connect to AWS public services privately, using only private IP addresses, which aligns with the company's requirement. Updating subnet route tables is unnecessary as interface endpoints are within the VPC and reachable via the local route. Modifying the security group is incorrect because the issue is with DNS resolution, not network access control. Creating a Route 53 private hosted zone with a conditional forwarder is a more complex solution that doesn't directly address the VPC endpoint's DNS resolution behavior for AWS services.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed