On-premises DNS servers must resolve hostnames defined in a GCP private zone. Which configuration provides that capability?
Choose an answer
Tap an option to check your answer.
Correct answer: Create Cloud DNS inbound endpoints and configure on-prem DNS forwarders to forward queries to those inbound endpoint IPs..
Why this is the answer
To allow on-premises DNS servers to resolve hostnames in a GCP private zone, you need to establish a path for those queries to reach Cloud DNS. Cloud DNS inbound endpoints provide specific IP addresses within your VPC network that act as targets for DNS queries originating from outside GCP, such as from your on-premises environment. By configuring your on-premises DNS forwarders to send queries for your private zone's domain to these inbound endpoint IPs, Cloud DNS can then resolve them. Creating an outbound forwarding zone is for forwarding queries from GCP to on-premises or other DNS servers, not the other way around. Exposing a private zone as public would make it accessible to the entire internet, which is insecure and not the purpose of a private zone. DNS peering zones are used for sharing private zones between different GCP VPC networks, not directly with on-premises networks.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed