An organization uses Shared VPC. Service project VMs attached to the host project’s VPC must resolve private DNS records. Where should the Cloud DNS private zone be created and attached?
Choose an answer
Tap an option to check your answer.
Correct answer: Create the private managed zone in the Shared VPC host project and attach it to the host VPC network so service project VMs using that network resolve the records..
Why this is the answer
In a Shared VPC setup, the host project centrally manages the network resources, including VPC networks. When you create a Cloud DNS private managed zone in the host project and attach it to the host VPC network, all service projects connected to that host network automatically inherit the ability to resolve records within that private zone. This simplifies management and ensures consistent DNS resolution across all attached service projects. Creating the zone in each service project is inefficient and defeats the purpose of centralized Shared VPC management. Private DNS zones are fully compatible with Shared VPC. Forwarding zones are used for resolving records in external DNS servers, not for internal private zones within the same VPC.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed