You manage hybrid name resolution. Requirements: (1) Split-horizon DNS for contoso.com with public records for the website and private records for internal services; (2) Auto-registration of Azure VM private A records; (3) Azure VMs must resolve on-prem contoso.local names and on-prem clients must resolve private contoso.com names hosted in Azure; (4) Avoid running custom DNS servers in Azure. Which two components should you deploy/configure? Choose two.
Choose an answer
Tap an option to check your answer.
Correct answer: An Azure DNS public zone for contoso.com and a separate Azure Private DNS zone contoso.com linked to VNets, enabling auto-registration on the hub VNet., Azure DNS Private Resolver with an inbound endpoint for on-prem DNS forwarders and an outbound endpoint with rules forwarding contoso.local to on-prem DNS..
Why this is the answer
The Azure DNS public zone for contoso.com handles public website records, while the Azure Private DNS zone for contoso.com, linked to VNets with auto-registration, provides split-horizon DNS and automatic A record creation for Azure VMs. The Azure DNS Private Resolver, with an inbound endpoint, allows on-premises DNS servers to forward queries for Azure-hosted private contoso.com records to Azure. Its outbound endpoint, with forwarding rules for contoso.local, enables Azure VMs to resolve on-premises resources. This combination meets all requirements without custom DNS servers. Azure-provided DNS alone doesn't support conditional forwarding or private zone hosting for hybrid scenarios. A Windows Server DNS VM is explicitly avoided. Private Link endpoints are for accessing Azure services privately, not for DNS resolution itself.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed