An on-premises environment needs to resolve records in a Route 53 private hosted zone (example.com) over a Direct Connect link to a VPC. What should the SysOps administrator configure so an on-premises DNS server can query the example.com private hosted zone?
Choose an answer
Tap an option to check your answer.
Correct answer: Create a Route 53 Resolver inbound endpoint and attach a security group that allows inbound TCP/UDP port 53 from the on-premises DNS servers..
Why this is the answer
To allow on-premises DNS servers to query private hosted zones in Route 53, an Inbound Resolver Endpoint is required. This endpoint provides an IP address within your VPC that on-premises DNS servers can forward queries to. The security group attached to this endpoint must permit inbound TCP/UDP port 53 traffic from the IP addresses of your on-premises DNS servers. The other options are incorrect because: An outbound endpoint is used for DNS queries originating from the VPC to on-premises DNS servers, not the other way around. Allowing outbound traffic from an inbound endpoint's security group is not the primary configuration for receiving queries; inbound rules are critical.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed