A company uses Amazon Route 53 Resolver DNS Firewall in a VPC to block all domains except those on an allow list. They worry that if the DNS Firewall becomes unresponsive, VPC resources will be affected because DNS queries might not resolve. To preserve application SLAs, DNS queries must continue to resolve even when Route 53 Resolver does not get a response from the DNS Firewall. What configuration change should the network engineer make to satisfy this requirement?
Choose an answer
Tap an option to check your answer.
Correct answer: Update the DNS Firewall VPC configuration to enable fail open for the VPC..
Why this is the answer
The correct option is to enable "fail open" for the VPC in the DNS Firewall configuration. When fail open is enabled, if the DNS Firewall becomes unresponsive or cannot process a query, it will allow the query to proceed to the upstream DNS resolver (e.g., Route 53 Resolver's default DNS service). This ensures that DNS resolution continues, preventing application outages and preserving SLAs, even if the firewall itself experiences issues. Disabling fail open would cause queries to fail if the firewall is unresponsive. DHCP options sets are not used to configure DNS Firewall fail open behavior; this setting is managed directly within the Route 53 Resolver DNS Firewall VPC configuration.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed