Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Amazon SOA-C03 Exam - Topic 3 Question 17 Discussion

A company operates compute resources in a VPC and in the company's on-premises data center. The company already has an AWS Direct Connect connection between the VPC and the on-premises data center.A CloudOps engineer needs to ensure that Amazon EC2 instances in the VPC can resolve DNS names for hosts in the on-premises data center.Which solution will meet this requirement with the LEAST amount of ongoing maintenance?
B) Create an Amazon Route 53 Resolver outbound endpoint. Add the IP addresses of an on-premises DNS server for the domain names that need to be forwarded.
A) Create an Amazon Route 53 private hosted zone. Populate the zone with the hostnames and IP addresses of the hosts in the on-premises data center.
C) Set up a forwarding rule for reverse DNS queries in Amazon Route 53 Resolver. Set the enableDnsHostnames attribute to true for the VPC.
D) Add the hostnames and IP addresses for the on-premises hosts to the /etc/hosts file of each EC2 instance.

Amazon SOA-C03 Exam - Topic 3 Question 17 Discussion

Actual exam question for Amazon's SOA-C03 exam
Question #: 17
Topic #: 3
[All SOA-C03 Questions]

A company operates compute resources in a VPC and in the company's on-premises data center. The company already has an AWS Direct Connect connection between the VPC and the on-premises data center.

A CloudOps engineer needs to ensure that Amazon EC2 instances in the VPC can resolve DNS names for hosts in the on-premises data center.

Which solution will meet this requirement with the LEAST amount of ongoing maintenance?

Show Suggested Answer Hide Answer
Suggested Answer: B

Amazon Route 53 Resolver outbound endpoints enable Amazon VPC resources to forward DNS queries to DNS servers that are outside of AWS, such as on-premises DNS servers. Because the company already has AWS Direct Connect in place, DNS queries can be routed privately from the VPC to the on-premises DNS infrastructure without using the public internet.

By creating an outbound endpoint and configuring forwarding rules for the on-premises domains, EC2 instances in the VPC can resolve DNS names dynamically using the existing authoritative DNS servers. This approach requires minimal ongoing maintenance because DNS records continue to be managed centrally in the on-premises DNS system.

Manually populating a private hosted zone or /etc/hosts files would require constant updates and does not scale. Reverse DNS forwarding alone does not solve forward name resolution.

Therefore, using Route 53 Resolver outbound endpoints is the correct solution.


Contribute your Thoughts:

0/2000 characters
Irma
1 day ago
B is definitely the way to go, less hassle in the long run!
upvoted 0 times
...
Lisbeth
7 days ago
I think C is overcomplicating things for a simple DNS issue.
upvoted 0 times
...
Leota
12 days ago
Wow, I didn't realize the /etc/hosts method was still a thing!
upvoted 0 times
...
Delmy
17 days ago
I disagree, A could work too, but it requires more manual updates.
upvoted 0 times
...
Sabine
22 days ago
Option B seems like the best choice for minimal maintenance.
upvoted 0 times
...
Buddy
27 days ago
Option D seems like a quick fix, but I doubt it would be practical for a larger environment with many EC2 instances.
upvoted 0 times
...
Andra
1 month ago
I recall something about Route 53 Resolver, but I'm uncertain if option C is the best choice for this scenario.
upvoted 0 times
...
Josefa
1 month ago
I'm not entirely sure, but I feel like option A might require more maintenance since you'd have to keep the hosted zone updated manually.
upvoted 0 times
...
Nicolette
1 month ago
I think option B sounds familiar; I remember it being mentioned in a practice question about DNS resolution between VPC and on-premises.
upvoted 0 times
...

Save Cancel