After creating a consumer-owned Private Service Connect endpoint that uses a private RFC1918 address, client applications in that VPC still fail to reach the managed service by hostname. What DNS change is required so the hostname resolves to the PSC endpoint IP for clients inside the VPC?
Choose an answer
Tap an option to check your answer.
Correct answer: Create a Cloud DNS private zone for the VPC and add an A record pointing the service hostname to the endpoint IP.
Why this is the answer
To resolve a service hostname to a Private Service Connect (PSC) endpoint's private IP address within a VPC, you need a private DNS solution. Creating a Cloud DNS private zone for your VPC and adding an A record that maps the service hostname to the PSC endpoint's internal IP address ensures that client applications within that VPC correctly resolve the hostname to the private endpoint. Creating a public Internet DNS A record is incorrect because PSC endpoints use private RFC1918 IP addresses, which are not reachable or resolvable via public DNS. Enabling Cloud DNS forwarding to 8.8.8.8 (Google Public DNS) is also incorrect as it would not resolve private IP addresses for internal services. Configuring Split-horizon DNS on the producer project only is insufficient; the consumer VPC needs its own DNS configuration to resolve the hostname to its specific PSC endpoint.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed