A company requires that all public DNS queries use an on-premises DNS security solution, except AWS service endpoints accessed via VPC endpoints. What steps should a network engineer perform to implement this design? (Choose three.)
Choose an answer
Tap an option to check your answer.
Correct answer: Create an Amazon Route 53 Resolver outbound endpoint. Associate this endpoint with the VPC., Create a system rule for the domain name amazonaws.com., Create a forwarding rule for the domain name "." (dot) with a target IP address of the on-premises DNS security solution..
Why this is the answer
To direct all public DNS queries to the on-premises solution, a forwarding rule for the root domain "." (dot) is needed, targeting the on-premises DNS security solution. This ensures all non-AWS queries go on-premises. An Amazon Route 53 Resolver outbound endpoint is required in the VPC to allow Route 53 Resolver to forward these queries to the on-premises DNS servers. To exempt AWS service endpoints accessed via VPC endpoints, a system rule for amazonaws.com is created. This rule ensures that queries for AWS services are resolved by Route 53 Resolver's internal DNS, allowing VPC endpoints to function correctly without being routed through the on-premises solution. Creating a system rule for "." (dot) would not work as intended for forwarding; system rules are for internal Route 53 Resolver behavior. A new DHCP options set would change the default DNS server for EC2 instances but wouldn't control forwarding for Route 53 Resolver itself. An inbound endpoint is for on-premises systems to query AWS, not for AWS to query on-premises.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed