Tailwind Logistics is evaluating two options to allow on-premises DNS clients to resolve Azure Private DNS names: (A) deploy a pair of HA VMs running BIND in the hub VNet and configure on-premises forwarders to send queries to those VMs; (B) deploy Azure Private DNS Resolver with inbound endpoints. From an operational and supportability standpoint which statement correctly compares these options?
Choose an answer
Tap an option to check your answer.
Correct answer: Azure Private DNS Resolver inbound endpoints provide a PaaS managed, supported solution that integrates with private zones without VM maintenance; BIND VMs are self-managed, require HA/patching and additional NSG/route config.
Why this is the answer
Azure Private DNS Resolver offers a Platform-as-a-Service (PaaS) solution for hybrid DNS resolution. Its inbound endpoints allow on-premises clients to query Azure Private DNS zones directly over VPN or ExpressRoute, without needing to deploy or manage virtual machines. This means Azure handles the underlying infrastructure, patching, and high availability, providing an SLA-backed service. In contrast, deploying BIND on virtual machines requires manual configuration for high availability, regular patching, and ongoing maintenance of the operating system and DNS software. Additionally, network security groups (NSGs) and routing tables would need to be configured to allow traffic to and from the BIND VMs. Therefore, the Private DNS Resolver is operationally simpler and more supportable. The BIND VM approach is not Azure-managed, and the resolver is not self-managed. Azure Private DNS Resolver can accept queries from on-premises. The solutions are not equivalent due to significant operational differences.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed