A company uses Amazon Route 53 Resolver in a hybrid DNS setup. Forwarding rules send queries for specific authoritative domains to on-premises DNS servers. A new mandate requires the company to log and query DNS traffic forwarded to those on-premises servers. The logs must include the source instance IP address and the DNS name requested as seen by Route 53 Resolver. Which solution meets these requirements?
Choose an answer
Tap an option to check your answer.
Correct answer: Enable Route 53 Resolver query logging on the relevant VPCs, send logs to Amazon CloudWatch Logs, and use CloudWatch Logs Insights to query the source IP and DNS name..
Why this is the answer
The correct solution is to enable Route 53 Resolver query logging. This feature is specifically designed to capture DNS queries processed by Route 53 Resolver, including those forwarded to on-premises servers. It provides details like the source IP address of the instance making the request and the DNS name queried, which directly fulfills the requirements. Sending these logs to Amazon CloudWatch Logs allows for centralized storage and easy querying using CloudWatch Logs Insights. VPC Traffic Mirroring captures network traffic, but it's not optimized for DNS query logging and would require complex filtering to extract the specific DNS information needed. VPC Flow Logs record network flow metadata (source/destination IP, port, protocol) but do not capture the actual DNS queries or the requested DNS names. Modifying forwarding rules to send logs to S3 is not a native Route 53 Resolver logging capability; Route 53 Resolver query logging is the dedicated service for this purpose.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed