After migrating an application to a VPC that is connected to the on-premises network via a Site-to-Site VPN, the application can no longer resolve internal hostnames that an on-premises DNS server answers. Which approach will allow the VPC-based application to resolve the on-premises domain names?
Choose an answer
Tap an option to check your answer.
Correct answer: Create a Route 53 Resolver outbound endpoint and configure forwarding rules so queries for the on-premises domain are forwarded to the on-premises DNS server..
Why this is the answer
The correct approach is to use a Route 53 Resolver outbound endpoint with forwarding rules. This allows DNS queries originating from the VPC for specific domains (like your on-premises domain) to be forwarded to your on-premises DNS servers over the Site-to-Site VPN connection. This integrates your on-premises DNS resolution with your VPC. Launching EC2 instances as DNS forwarders is a manual and less scalable solution compared to Route 53 Resolver. It adds operational overhead. Establishing two Direct Connect connections and aggregating them with a LAG is an expensive and unnecessary network change for a DNS resolution issue when a VPN is already in place; it also doesn't directly solve the DNS forwarding problem. Creating a public Route 53 hosted zone for an internal, on-premises domain is a security risk and incorrect for internal name resolution, as it would expose internal hostnames publicly and wouldn't use the on-premises DNS server.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed