Mobile banking apps are running on Amazon EC2 instances in a VPC and need to resolve DNS names in an on-premises Active Directory domain. The on-premises data center connects to AWS over AWS Direct Connect. Which option provides DNS resolution to the on-premises AD domain for instances in the VPC with the least administrative overhead?
Choose an answer
Tap an option to check your answer.
Correct answer: Create Amazon Route 53 Resolver endpoints and add conditional forwarding rules to enable DNS namespace resolution between the on-premises data center and the VPC..
Why this is the answer
Creating Amazon Route 53 Resolver endpoints and conditional forwarding rules is the most efficient solution. This allows DNS queries for the on-premises Active Directory domain to be forwarded directly to the on-premises DNS servers via the Direct Connect link, and vice-versa, without requiring additional server management. This minimizes administrative overhead. Provisioning EC2 instances as caching DNS servers adds unnecessary management burden and doesn't directly integrate with the on-premises DNS for authoritative resolution. Creating a Route 53 private hosted zone with NS records pointing to on-premises DNS servers is not the intended use for hybrid DNS resolution and lacks the conditional forwarding capabilities of Route 53 Resolver. Provisioning a new Active Directory domain controller in the VPC and configuring a trust is a complex solution primarily for authentication and authorization, not just DNS resolution, and involves significant administrative overhead.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed