Northwind Pharmaceuticals wants VM hosts in 6 spoke VNets to automatically register their hostnames into a shared Azure Private DNS zone 'prod.internal.northwind.com' created in the hub subscription. The team also needs to control which VNets can perform registrations. What is the correct sequence and configuration to enable auto-registration and restrict registration to a single VNet?
Choose an answer
Tap an option to check your answer.
Correct answer: Create the private DNS zone in the hub subscription; for each spoke VNet link enable auto-registration. To restrict registrations, remove auto-registration on all spokes and enable it only on the VNet that hosts the VMs you want registered..
Why this is the answer
The correct approach involves creating the Azure Private DNS zone in the central hub subscription, as this allows for centralized management and sharing across spoke VNets. For auto-registration, you link each spoke VNet to this private DNS zone. The key to restricting registrations is to enable auto-registration only on the specific VNet link where you want VMs to register their hostnames. If auto-registration is enabled on multiple VNet links, VMs from all those linked VNets will register. Therefore, to restrict, you enable it only on the desired VNet's link. Creating separate zones in each spoke VNet would prevent centralized management and auto-replication. Microsoft Defender for DNS is a security service, not for controlling auto-registration. Auto-registration is configured per VNet link, not at the zone level globally overriding link settings.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed