Fabrikam runs services in Azure and needs to forward DNS queries from Azure VNets for on-premises-only namespaces (e.g., corp.fabrikam.local) back to on-premises DNS servers. They plan to use Azure Private DNS Resolver's outbound capabilities and a forwarding ruleset. What is the correct architecture to ensure queries from Azure are forwarded to on-premises authoritative servers?
Choose an answer
Tap an option to check your answer.
Correct answer: Create a forwarding ruleset containing conditional forward rules for corp.fabrikam.local pointing to on-premises DNS IP addresses, and associate that ruleset with the hub VNet; deploy an outbound endpoint in the hub VNet so the resolver can forward queries to on-premises.
Why this is the answer
The correct option describes the architecture for using Azure Private DNS Resolver to forward on-premises DNS queries. An outbound endpoint in the hub VNet allows the resolver to send queries out of Azure, specifically to the on-premises DNS servers. The forwarding ruleset, associated with the hub VNet, contains conditional forward rules that direct queries for corp.fabrikam.local to the specified on-premises DNS IP addresses. The first incorrect option incorrectly suggests using public IPs for the outbound endpoint and forwarding to FQDNs instead of IP addresses. The third incorrect option describes a different scenario (on-premises registration to Azure DNS) and doesn't address forwarding queries from Azure to on-premises. The fourth incorrect option incorrectly suggests using a private DNS zone for on-premises names and configuring NSG rules for 8.8.8.8, which is irrelevant for forwarding to on-premises servers.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed