VNet1 contains an Azure Firewall (FW1) and 150 virtual machines. VNet1 is linked to a private DNS zone contoso.com, and all VMs are registered in that zone. VNet1 is connected to on-premises via ExpressRoute. You need on-premises DNS servers to resolve names in the contoso.com private zone. Which two actions should you take? (Choose two.)
Choose an answer
Tap an option to check your answer.
Correct answer: For FW1, enable DNS proxy., On the on-premises DNS servers, configure forwarders that point to the frontend IP address of FW1..
Why this is the answer
To allow on-premises DNS servers to resolve names in an Azure private DNS zone, you need a mechanism to forward those requests from on-premises to Azure's DNS resolvers. Azure Firewall's DNS Proxy feature (correct) enables the firewall to act as an intermediary, forwarding DNS queries to Azure DNS. By configuring on-premises DNS servers to forward requests for contoso.com to the frontend IP address of FW1 (correct), these requests will then be handled by the firewall and resolved by Azure DNS. Modifying VNet1's DNS settings would only affect resources within VNet1, not on-premises. Configuring custom DNS servers for FW1 is not sufficient; the DNS proxy must also be enabled to forward requests. Forwarding to 168.63.129.16 directly from on-premises is incorrect because that IP is only reachable from within Azure virtual networks.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed